Impact
An issue within the ConfirmNameConstraints() function of wolfSSL causes the library to reject otherwise valid certificates that lack a Subject Alternative Name extension. This logical flaw allows an attacker to trigger a denial of service in any wolfSSL‑based TLS client by providing crafted Certificate Authority certificates. The impact is a client‑side service interruption; no elevation of privilege or data exfiltration is indicated.
Affected Systems
WolfSSL versions 5.9.1 and 5.9.2 are affected. The vulnerability exists in the wolfcrypt/asn.c component and applies to applications that rely on these specific library releases for TLS client functionality.
Risk and Exploitability
The CVSS score is not specified in the available data, and the EPSS score is unavailable, indicating no publicly documented exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not been widely observed in the wild. Attackers would need to supply malicious CA certificates to the client; the vulnerability is triggered by normal certificate validation flows, meaning exploitation can occur during any TLS connection that encounters the crafted CA. Because the flaw leads to a client denial of service, the risk to confidentiality and integrity is low, but availability is compromised.
OpenCVE Enrichment