Peer Certificate Verification Bypass in wolfSSL Affects Multiple Products
CVE-2026-93302

8.3HIGH

Key Information:

Vendor

Wolfssl

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-93302?

A bypass issue in wolfSSL's MatchTrustedPeer function allows forged certificate authority (CA) clones to pass verification checks. This flaw impacts any builds where the macro WOLFSSL_TRUST_PEER_CERT is enabled, allowing the malicious (D)TLS server to potentially bypass authentication by manipulating the CA certificates. The vulnerability extends when OPENSSL_COMPATIBLE_DEFAULTS is also defined, affecting all CA certificate loading within several applications including nginx, haproxy, stunnel, and more. To safeguard against this vulnerability, users are advised to update to the latest version of wolfSSL, apply the provided patch, or modify their build configuration to disable the problematic macros.

Affected Version(s)

wolfSSL 5.3.0 <= 5.9.2

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anthropic OSS program
.