Improper Certificate Validation in wolfSSL - CVE-2026-94417
Published: October 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass certificate revocation checking.
The vulnerability exists due to improper certificate validation in ProcessPeerCerts() when processing a peer certificate without an Authority Information Access OCSP URL. A remote attacker can present a revoked certificate without an OCSP responder URL to bypass certificate revocation checking.
The issue requires OCSP and CRL checking to be enabled on the same certificate manager or context with a CRL loaded.