目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-94418— WOLFSSL 小证书验证下日期错误掩盖签名失败漏洞

一分钟漏洞结论

影响对象
wolfSSL wolfSSL
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在启用 宏的情况下, 函数为了降低峰值内存占用,将证书签名验证与解析过程分离执行,然后再合并两者的结果。然而,该函数仅在解析成功(返回 0)时才合并签名验证结果,因此任何解析错误都会掩盖签名验证失败的结果。 此外, 函数仅在 验证通过之后,才会执行日期有效性、名称约束和关键扩展检查。这种将签名验证分离的做法,颠倒了原本使“覆盖日期错误”成为合理策略的执行顺序,导致 错误码无法在任何地方被正确上报。 攻击者无需从真实公钥基础设施(PKI)获取任何密钥材料,也无需 compromise(攻破)证书颁发机构(CA)。攻击

CVSS 2.3 · Low EPSS 0.05% · P0
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-94418 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY
来源: CVE Program / CVE List V5
Vulnerability Description
Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to keep peak memory down, then merges the two results, but it merged the signature result back only when the parse returned 0, so any parse error hid it. ParseCertRelative() reaches its validity-date, name-constraint and critical-extension checks only after ConfirmSignature() has passed, so splitting the signature check out inverts the precedence that makes "override date errors" a sound policy, and ASN_SIG_CONFIRM_E is never surfaced anywhere. The attacker needs no key material from the real PKI and no CA compromise: a self-made certificate carrying the expected subject name, the trusted CA's subject as its issuer, arbitrary bytes where the signature goes, a validity window in the past and the attacker's own key pair is sufficient. Affected builds define WOLFSSL_SMALL_CERT_VERIFY, which is off by default, is not set implicitly by any platform or preset header, and is not reachable from any CMake option; the autotools routes are --enable-lowresource, --enable-leantls, --enable-tinytls13=cert and --enable-tinytls13=mutualauth, and examples/configs/user_settings_embedded.h reaches it through WC_CFG_SMALL_CERT_VERIFY, which ships as 0, while neither --enable-all nor --enable-distro enables it at all. The application must additionally install a verify callback through wolfSSL_CTX_set_verify() or wolfSSL_set_verify() with WOLFSSL_VERIFY_PEER that returns 1 for ASN_BEFORE_DATE_E or ASN_AFTER_DATE_E; wolfSSL ships this exact shape as myVerify() in wolfssl/test.h under VERIFY_OVERRIDE_DATE_ERR, which examples/client -D selects. An application with no callback, or whose callback returns preverify for date errors, still fails the handshake, and wolfSSL_CertManagerVerifyBuffer() and wc_CheckCertSignature() report ASN_SIG_CONFIRM_E correctly in the same binary. TLS 1.2 and TLS 1.3 are affected in both directions, and DTLS reaches the same function; where the forged certificate is a chain certificate the callback's consent causes it to be cached in the WOLFSSL_CTX certificate manager, so an exposed deployment must restart the context or the process rather than merely reconnect.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
密码学签名的验证不恰当
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
wolfSSL wolfSSL 3.15.5 ~ 5.9.2 -

二、漏洞 CVE-2026-94418 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-94418 的情报信息

请登录查看更多情报信息。

CVE-2026-94418 其他参考 (1)

同批安全公告 · wolfSSL · 2026-09-27 · 共 11 条

CVE-2026-93302 8.3 HIGH 可信对等证书匹配忽略公钥,允许伪造CA克隆
CVE-2026-89136 8.3 HIGH 客户端接受未请求的RawPublicKey服务器证书类型
CVE-2026-89102 8.3 HIGH OCSP stapling v2多接受非CA链证书作为颁发者
CVE-2026-93304 6.3 MEDIUM (D)TLS 1.2 客户端接受早期 ChangeCipherSpec 漏洞
CVE-2026-89133 6.3 MEDIUM 中间CA未强制执行NameConstraints策略
CVE-2026-89134 6.3 MEDIUM Subject CN名称约束检查在非DNS SAN存在时被绕过
CVE-2026-89135 6.3 MEDIUM X509_verify_cert失败导致未验证CA保留在共享CertManager
CVE-2026-15442 2.3 LOW 双向(D)TLS关闭期间的堆使用后释放漏洞
CVE-2026-94419 2.3 LOW 客户端会话缓存引用中毒导致与错误服务器恢复连接
CVE-2026-94417 2.3 LOW 启用OCSP且证书无OCSP URL时跳过CRL检查

IV. Related Vulnerabilities

V. Comments for CVE-2026-94418

暂无评论


发表评论