Improper Certificate Validation in wolfSSL - CVE-2026-89133
Published: October 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to use certificates for unauthorized hostnames.
The vulnerability exists due to improper certificate validation in X.509 NameConstraints processing when validating a certificate chain with an unconstrained intermediate CA. A remote attacker can present a certificate chain for an unauthorized hostname to use certificates for unauthorized hostnames.
The issue affects certificate validation where name constraint extensions are used.