SB2026100555 - Multiple vulnerabilities in wolfSSL



SB2026100555 - Multiple vulnerabilities in wolfSSL

Published: October 5, 2026

Security Bulletin ID SB2026100555
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 11
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 11 vulnerabilities.


1) Improper Certificate Validation (CVE-ID: CVE-2026-93302)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass peer authentication.

The vulnerability exists due to improper certificate validation in the trusted peer certificate verification path when processing a peer certificate. A remote attacker can present a forged certificate that reuses trusted certificate identity fields to bypass peer authentication.

Exploitation requires knowledge of the CA certificates loaded as trusted peer certificates.


2) Improper Certificate Validation (CVE-ID: CVE-2026-89102)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to forge certificates for arbitrary identities.

The vulnerability exists due to improper certificate validation in RFC 6961 multiple OCSP response stapling when processing a peer certificate chain. A remote attacker can present a certificate chain containing an unauthorized certificate authority to forge certificates for arbitrary identities.

Exploitation requires a certificate and private key that chain to a CA trusted by the client, and the affected client configuration uses OCSP multi stapling.


3) Improper Certificate Validation (CVE-ID: CVE-2026-89136)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass server authentication.

The vulnerability exists due to improper certificate validation in raw public key handling when processing an unsolicited server_cert_type=RawPublicKey. A remote attacker can send an unsolicited raw public key certificate type to bypass server authentication.

Only builds with raw public key support enabled are affected.


4) Improper Authentication (CVE-ID: CVE-2026-93304)

CWE-ID: CWE-287 - Improper Authentication

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to impersonate a server.

The vulnerability exists due to improper state management in the TLS 1.2 and DTLS 1.2 handshake when receiving an out-of-order ChangeCipherSpec message before ClientKeyExchange. A remote attacker can send an out-of-order ChangeCipherSpec message to impersonate a server.

Certificate-suite exploitation requires a man-in-the-middle position, while PSK connections can be attacked by a fake server without knowledge of the PSK.


5) Improper Certificate Validation (CVE-ID: CVE-2026-89133)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to use certificates for unauthorized hostnames.

The vulnerability exists due to improper certificate validation in X.509 NameConstraints processing when validating a certificate chain with an unconstrained intermediate CA. A remote attacker can present a certificate chain for an unauthorized hostname to use certificates for unauthorized hostnames.

The issue affects certificate validation where name constraint extensions are used.


6) Improper Certificate Validation (CVE-ID: CVE-2026-89134)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to use certificates for unauthorized hostnames.

The vulnerability exists due to improper certificate validation in the subject CN dNSName name-constraint check when processing a certificate with a non-dNSName subject alternative name. A remote attacker can present a certificate with an out-of-scope common name to use certificates for unauthorized hostnames.

The certificate must lack a dNSName SAN while containing another SAN type.


7) Improper Certificate Validation (CVE-ID: CVE-2026-89135)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass certificate validation in sibling consumers.

The vulnerability exists due to improper certificate validation in X509_verify_cert when a certificate verification attempt fails. A remote attacker can cause a failed certificate verification that adds an unverified CA to the shared certificate manager to bypass certificate validation in sibling consumers.

The issue requires an application using X509_verify_cert in an OPENSSL_EXTRA build.


8) Use-after-free (CVE-ID: CVE-2026-15442)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a heap-use-after-free.

The vulnerability exists due to a heap-use-after-free in the TLS shutdown state handling when an application reads data after a partial wolfSSL_read() and bidirectional wolfSSL_shutdown(). A remote attacker can continue sending data during shutdown to cause a heap-use-after-free.

The condition requires a partial read, which can occur when the application uses a small user buffer.


9) Improper Certificate Validation (CVE-ID: CVE-2026-94417)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass certificate revocation checking.

The vulnerability exists due to improper certificate validation in ProcessPeerCerts() when processing a peer certificate without an Authority Information Access OCSP URL. A remote attacker can present a revoked certificate without an OCSP responder URL to bypass certificate revocation checking.

The issue requires OCSP and CRL checking to be enabled on the same certificate manager or context with a CRL loaded.


10) Improper Certificate Validation (CVE-ID: CVE-2026-94418)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass certificate signature validation.

The vulnerability exists due to improper certificate validation in ProcessPeerCertParse() when merging certificate signature and parsing results. A remote attacker can present a self-made certificate with an invalid signature and an expired validity period to bypass certificate signature validation.

The issue requires WOLFSSL_SMALL_CERT_VERIFY and a peer-verification callback that overrides certificate date errors.


11) Authentication Bypass by Primary Weakness (CVE-ID: CVE-2026-94419)

CWE-ID: CWE-305 - Authentication Bypass by Primary Weakness

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to impersonate a previously authenticated server.

The vulnerability exists due to improper session management in the process-global SessionCache when handling legacy client session references. A remote attacker can cause a session cache entry to be overwritten through a matching TLS session ID to impersonate a previously authenticated server.

The issue requires the legacy wolfSSL_get_session() or SSL_get_session() flow followed by wolfSSL_set_session() and affects TLS 1.2 and earlier or DTLS 1.2 and earlier.


Remediation

Install update from vendor's website.