Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-94418— Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY

Quick assessment

Affected
wolfSSL wolfSSL
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在启用 宏的情况下, 函数为了降低峰值内存占用,将证书签名验证与解析过程分离执行,然后再合并两者的结果。然而,该函数仅在解析成功(返回 0)时才合并签名验证结果,因此任何解析错误都会掩盖签名验证失败的结果。 此外, 函数仅在 验证通过之后,才会执行日期有效性、名称约束和关键扩展检查。这种将签名验证分离的做法,颠倒了原本使“覆盖日期错误”成为合理策略的执行顺序,导致 错误码无法在任何地方被正确上报。 攻击者无需从真实公钥基础设施(PKI)获取任何密钥材料,也无需 compromise(攻破)证书颁发机构(CA)。攻击

CVSS 2.3 · Low EPSS 0.05% · P0
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94418

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY
Source: CVE Program / CVE List V5
Vulnerability Description
Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to keep peak memory down, then merges the two results, but it merged the signature result back only when the parse returned 0, so any parse error hid it. ParseCertRelative() reaches its validity-date, name-constraint and critical-extension checks only after ConfirmSignature() has passed, so splitting the signature check out inverts the precedence that makes "override date errors" a sound policy, and ASN_SIG_CONFIRM_E is never surfaced anywhere. The attacker needs no key material from the real PKI and no CA compromise: a self-made certificate carrying the expected subject name, the trusted CA's subject as its issuer, arbitrary bytes where the signature goes, a validity window in the past and the attacker's own key pair is sufficient. Affected builds define WOLFSSL_SMALL_CERT_VERIFY, which is off by default, is not set implicitly by any platform or preset header, and is not reachable from any CMake option; the autotools routes are --enable-lowresource, --enable-leantls, --enable-tinytls13=cert and --enable-tinytls13=mutualauth, and examples/configs/user_settings_embedded.h reaches it through WC_CFG_SMALL_CERT_VERIFY, which ships as 0, while neither --enable-all nor --enable-distro enables it at all. The application must additionally install a verify callback through wolfSSL_CTX_set_verify() or wolfSSL_set_verify() with WOLFSSL_VERIFY_PEER that returns 1 for ASN_BEFORE_DATE_E or ASN_AFTER_DATE_E; wolfSSL ships this exact shape as myVerify() in wolfssl/test.h under VERIFY_OVERRIDE_DATE_ERR, which examples/client -D selects. An application with no callback, or whose callback returns preverify for date errors, still fails the handshake, and wolfSSL_CertManagerVerifyBuffer() and wc_CheckCertSignature() report ASN_SIG_CONFIRM_E correctly in the same binary. TLS 1.2 and TLS 1.3 are affected in both directions, and DTLS reaches the same function; where the forged certificate is a chain certificate the callback's consent causes it to be cached in the WOLFSSL_CTX certificate manager, so an exposed deployment must restart the context or the process rather than merely reconnect.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
密码学签名的验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wolfSSL wolfSSL 3.15.5 ~ 5.9.2 -

II. Public POCs for CVE-2026-94418

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94418

请登录查看更多情报信息。

Other References for CVE-2026-94418 (1)

Same Patch Batch · wolfSSL · 2026-09-27 · 11 CVEs total

CVE-2026-93302 8.3 HIGH Trusted peer certificate match ignores public key, allowing forged CA clones
CVE-2026-89136 8.3 HIGH Client accepts unsolicited RawPublicKey server certificate type
CVE-2026-89102 8.3 HIGH OCSP stapling v2 multi accepts non-CA chain certificates as issuers
CVE-2026-93304 6.3 MEDIUM (D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange
CVE-2026-89133 6.3 MEDIUM NameConstraints not enforced across unconstrained intermediate CA
CVE-2026-89134 6.3 MEDIUM Subject CN name-constraint check bypassed when non-DNS SAN present
CVE-2026-89135 6.3 MEDIUM Failed X509_verify_cert leaves unverified CA in shared CertManager
CVE-2026-15442 2.3 LOW Heap use-after-free on read during bidirectional (D)TLS shutdown
CVE-2026-94419 2.3 LOW Client session cache reference poisoning allows resumption with wrong server
CVE-2026-94417 2.3 LOW CRL check skipped when OCSP enabled and certificate has no OCSP URL

IV. Related Vulnerabilities

V. Comments for CVE-2026-94418

No comments yet


Leave a comment