Improper Certificate Validation in wolfSSL - CVE-2026-89136
Published: October 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass server authentication.
The vulnerability exists due to improper certificate validation in raw public key handling when processing an unsolicited server_cert_type=RawPublicKey. A remote attacker can send an unsolicited raw public key certificate type to bypass server authentication.
Only builds with raw public key support enabled are affected.