Certificate Name-Constraint Issue in wolfSSL Software
CVE-2026-89134

6.3MEDIUM

Key Information:

Vendor

Wolfssl

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-89134?

A certificate vulnerability has been identified in wolfSSL, where a certificate lacking a dNSName Subject Alternative Name (SAN) but containing another SAN type can bypass the Subject Common Name (CN) dNSName name-constraint check. This occurs due to inadequate validation logic, allowing the acceptance of out-of-scope CN values when fallback conditions are met. This issue stems from an incomplete fix of a prior vulnerability, highlighting the need for robust certificate validation to prevent unauthorized access.

Affected Version(s)

wolfSSL 5.9.2

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jorge Milla (Pig-Tail)
.