Description
An issue in the ConfirmNameConstraints() function (wolfcrypt/src/asn.c) of wolfSSL v5.9.1 and v5.9.2 allows attackers to cause a Denial of Service (DoS) via providing crafted Certificate Authority certificates, leading to valid certificates without SAN to be incorrectly rejected by wolfSSL-based TLS clients.
Published: 2026-10-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service via TLS client certificate validation failure
Action: Assess Impact
AI Analysis

Impact

An issue within the ConfirmNameConstraints() function of wolfSSL causes the library to reject otherwise valid certificates that lack a Subject Alternative Name extension. This logical flaw allows an attacker to trigger a denial of service in any wolfSSL‑based TLS client by providing crafted Certificate Authority certificates. The impact is a client‑side service interruption; no elevation of privilege or data exfiltration is indicated.

Affected Systems

WolfSSL versions 5.9.1 and 5.9.2 are affected. The vulnerability exists in the wolfcrypt/asn.c component and applies to applications that rely on these specific library releases for TLS client functionality.

Risk and Exploitability

The CVSS score is not specified in the available data, and the EPSS score is unavailable, indicating no publicly documented exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not been widely observed in the wild. Attackers would need to supply malicious CA certificates to the client; the vulnerability is triggered by normal certificate validation flows, meaning exploitation can occur during any TLS connection that encounters the crafted CA. Because the flaw leads to a client denial of service, the risk to confidentiality and integrity is low, but availability is compromised.

Generated by OpenCVE AI on October 8, 2026 at 19:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade wolfSSL to a patched release that addresses the name‑constraint validation issue (5.9.3 or later).
  • If an upgrade is not immediately possible, implement additional certificate validation logic in the application to enforce SAN presence and reject certificates with missing SANs before passing them to wolfSSL.
  • Consider migrating to an alternative TLS library that does not exhibit this flaw until a fix is applied.

Generated by OpenCVE AI on October 8, 2026 at 19:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Wolfssl
Wolfssl wolfssl
Vendors & Products Wolfssl
Wolfssl wolfssl

Thu, 08 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Title DoS via Misvalidated Certificate Name Constraints in wolfSSL
Weaknesses CWE-20

Thu, 08 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description An issue in the ConfirmNameConstraints() function (wolfcrypt/src/asn.c) of wolfSSL v5.9.1 and v5.9.2 allows attackers to cause a Denial of Service (DoS) via providing crafted Certificate Authority certificates, leading to valid certificates without SAN to be incorrectly rejected by wolfSSL-based TLS clients.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-08T20:16:24.707Z

Reserved: 2026-09-22T00:00:00.000Z

Link: CVE-2026-95208

cve-icon Vulnrichment

Updated: 2026-10-08T20:16:20.987Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T16:18:01.420

Modified: 2026-10-08T21:34:48.800

Link: CVE-2026-95208

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:15:06Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-295

    Improper Certificate Validation