#VU125925 Improper Certificate Validation in wolfSSL - CVE-2026-5263
Published: April 14, 2026
wolfSSL
wolfSSL
Description
The vulnerability allows a remote attacker to bypass certificate name constraints validation.
The vulnerability exists due to improper certificate validation in wolfcrypt/src/asn.c when verifying certificate chains containing URI SAN entries. A remote attacker can supply a crafted certificate chain to bypass certificate name constraints validation.
Exploitation requires a compromised or malicious subordinate CA.