Improper Certificate Validation in wolfSSL - CVE-2026-89102
Published: October 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to forge certificates for arbitrary identities.
The vulnerability exists due to improper certificate validation in RFC 6961 multiple OCSP response stapling when processing a peer certificate chain. A remote attacker can present a certificate chain containing an unauthorized certificate authority to forge certificates for arbitrary identities.
Exploitation requires a certificate and private key that chain to a CA trusted by the client, and the affected client configuration uses OCSP multi stapling.