CVE-2026-5501: fallo de gravedad alta en wolfSSL
Improper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificates
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.6epss 0.2%
probabilidad de explotación
0.2%top 89% de las CVE
explotación observada
noninguna fuente lo reporta
wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker supplies an untrusted intermediate with Basic Constraints `CA:FALSE` that is legitimately signed by a trusted root. An attacker who obtains any leaf certificate from a trusted CA (e.g. a free DV cert from Let's Encrypt) can forge a certificate for any subject name with any public key and arbitrary signature bytes, and the function returns `WOLFSSL_SUCCESS` / `X509_V_OK`. The native wolfSSL TLS handshake path (`ProcessPeerCerts`) is not susceptible and the issue is limited to applications using the OpenSSL compatibility API directly, which would include integrations of wolfSSL into nginx and haproxy.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
wolfSSL · wolfSSLCVEs relacionadas — wolfSSL
En el mismo producto, de las más peligrosas a las menos.
CVE-2017-13099HIGHwolfSSL Bleichenbacher/ROBOTEPSS 24.9%CVE-2017-2800HIGHCVE-2017-2800EPSS 8.5%CVE-2024-0901HIGHSEGV and out of bounds memory read from malicious packetEPSS 0.7%CVE-2023-3724CRITICALTLS 1.3 client issue handling malicious server when not including a KSE and PSK extensionEPSS 0.7%CVE-2026-3548HIGHBuffer overflow in CRL number parsing in wolfSSLEPSS 0.6%CVE-2023-6936MEDIUM Heap-buffer over-read with WOLFSSL_CALLBACKSEPSS 0.6%