Certificate Name-Constraint Issue in wolfSSL Software
CVE-2026-89134
6.3MEDIUM
What is CVE-2026-89134?
A certificate vulnerability has been identified in wolfSSL, where a certificate lacking a dNSName Subject Alternative Name (SAN) but containing another SAN type can bypass the Subject Common Name (CN) dNSName name-constraint check. This occurs due to inadequate validation logic, allowing the acceptance of out-of-scope CN values when fallback conditions are met. This issue stems from an incomplete fix of a prior vulnerability, highlighting the need for robust certificate validation to prevent unauthorized access.
Affected Version(s)
wolfSSL 5.9.2
