TLS Vulnerability in wolfSSL Affecting Raw Public Key Authentication
CVE-2026-89136
8.3HIGH
What is CVE-2026-89136?
A vulnerability exists in wolfSSL that affects the TLS 1.2, 1.3, and DTLS 1.2 protocols when using Raw Public Key (RPK) authentication. Specifically, the client side of these connections can erroneously accept unsolicited server certificates of type Raw Public Key. This issue allows malicious actors to bypass standard authentication procedures, as the server can present itself without proper verification. RPK is not enabled by default and requires specific configurations to be activated, such as --enable-rpk. Users are advised to review their configurations and ensure that they implement adequate security measures to mitigate this risk.
Affected Version(s)
wolfSSL 5.6.0 <= 5.9.2
References
CVSS V4
Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Christos Papakonstantinou (Cantina Security)
