目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-94419— 客户端会话缓存引用中毒导致与错误服务器恢复连接

一分钟漏洞结论

影响对象
wolfSSL wolfSSL
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

如果未定义 , 不会返回一个完整的会话对象(session object),而是返回一个形如 的 引用,指向进程全局的 。此时, 仅根据该哈希值进行验证。 由于 TLS 1.2 的会话 ID 由服务器选择并以明文形式发送, 会将具有相同会话 ID 的其他服务器的会话匹配到缓存中,并用该服务器的主密钥(master secret)、密码套件(cipher suite)和协议版本覆盖客户端本地的会话条目,而引用句柄(handle)仍继续有效。在写路径上,没有任何机制比较对等方、应用程序配置的服务端 ID 或 。因此,通

CVSS 2.3 · Low EPSS 0.08% · P0
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-94419 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Client session cache reference poisoning allows resumption with wrong server
来源: CVE Program / CVE List V5
Vulnerability Description
Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the form {row, index, hash(sessionID)} into the process-global SessionCache, and ClientSessionToSession() validates it against that hash alone. Because the TLS 1.2 session ID is chosen by the server and sent in clear, AddSessionToCache() matches any other server's session on the same ID and overwrites the client-side entry with that server's master secret, cipher suite and version, while the handle continues to resolve; nothing on the write path compares the peer, the application's server ID or the WOLFSSL_CTX. Resuming through the handle then produces an abbreviated handshake in which no Certificate message is sent, so neither chain verification nor wolfSSL_check_domain_name() runs, and the attacker is accepted as the original server for the whole of that connection. Affected builds are those leaving NO_SESSION_CACHE_REF, NO_SESSION_CACHE, NO_CLIENT_CACHE and TITAN_SESSION_CACHE all undefined, which includes a plain ./configure, --enable-opensslextra and --enable-opensslall; fifteen integration options define NO_SESSION_CACHE_REF and are therefore not affected, among them --enable-all, --enable-distro, --enable-curl, --enable-nginx, --enable-haproxy, --enable-stunnel, --enable-wpas and the rest of the OPENSSL_COMPATIBLE_DEFAULTS family, and --enable-leanpsk, --enable-leantls, --enable-lowresource and --enable-tinytls13 disable the cache outright. The application must use the legacy reference flow, wolfSSL_get_session() or SSL_get_session() followed by wolfSSL_set_session(); wolfSSL_get1_session() returns the session object itself and is not affected, nor are wolfSSL_SetServerID() lookups. Only TLS 1.2 and below and DTLS 1.2 and below are reachable, since TLS 1.3 and ticket resumption with an empty ServerHello session ID both use a client-chosen cache key. The poisoned entry lives in the process-global cache, so it crosses WOLFSSL_CTX boundaries and persists until the entry is evicted or the session times out, 500 seconds by default. Releases v5.3.0 through v5.9.2 are affected; the fix adds a per-write generation counter to the cache and raises WOLFSSL_CACHE_VERSION from 2 to 3, so a cache persisted by an older build is rejected by a fixed one.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
wolfSSL wolfSSL 5.3.0 ~ 5.9.2 -

二、漏洞 CVE-2026-94419 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-94419 的情报信息

请登录查看更多情报信息。

CVE-2026-94419 其他参考 (1)

同批安全公告 · wolfSSL · 2026-09-27 · 共 11 条

CVE-2026-93302 8.3 HIGH 可信对等证书匹配忽略公钥,允许伪造CA克隆
CVE-2026-89136 8.3 HIGH 客户端接受未请求的RawPublicKey服务器证书类型
CVE-2026-89102 8.3 HIGH OCSP stapling v2多接受非CA链证书作为颁发者
CVE-2026-93304 6.3 MEDIUM (D)TLS 1.2 客户端接受早期 ChangeCipherSpec 漏洞
CVE-2026-89133 6.3 MEDIUM 中间CA未强制执行NameConstraints策略
CVE-2026-89134 6.3 MEDIUM Subject CN名称约束检查在非DNS SAN存在时被绕过
CVE-2026-89135 6.3 MEDIUM X509_verify_cert失败导致未验证CA保留在共享CertManager
CVE-2026-15442 2.3 LOW 双向(D)TLS关闭期间的堆使用后释放漏洞
CVE-2026-94418 2.3 LOW WOLFSSL 小证书验证下日期错误掩盖签名失败漏洞
CVE-2026-94417 2.3 LOW 启用OCSP且证书无OCSP URL时跳过CRL检查

IV. Related Vulnerabilities

V. Comments for CVE-2026-94419

暂无评论


发表评论