X.509 Name Constraint Bypass in wolfSSL Products
CVE-2026-6731

6MEDIUM

Key Information:

Vendor

Wolfssl

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-6731?

A bypass vulnerability has been identified in wolfSSL that allows an attacker to present a certificate with a Subject Common Name (CN) that violates the issuing certificate authority's (CA) DNS name constraints. If exploited, this could permit unauthorized acceptance of certificates, potentially undermining certificate validation processes. This issue emphasizes the importance of strict validation mechanisms in cryptographic applications.

Affected Version(s)

wolfSSL 3.9.10 <= 5.9.1

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

d0sf3t (Aradex)
.