Improper Certificate Validation in wolfSSL - CVE-2026-89134
Published: October 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to use certificates for unauthorized hostnames.
The vulnerability exists due to improper certificate validation in the subject CN dNSName name-constraint check when processing a certificate with a non-dNSName subject alternative name. A remote attacker can present a certificate with an out-of-scope common name to use certificates for unauthorized hostnames.
The certificate must lack a dNSName SAN while containing another SAN type.