CVE-2026-10592: Wildcard DNS SAN bypasses CA name-constraint checks
Published Jun 25, 2026
·Updated
Certificates with wildcard DNS SANs (e.g. .example.com) bypassed CA name-constraint checks. A certificate with a wildcard DNS SAN that should be rejected by the issuing CA's permitted/excluded DNS name constraints could be accepted.
Affected Software
1 affected component
wolfSSL wolfssl>=3.9.10<5.9.2
Remediation
Patch Available
Event History
Jun 25, 2026
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-10592?
CVE-2026-10592 has a medium severity rating of 6.3 according to the CVSS scoring system.
2
How do I fix CVE-2026-10592?
To address CVE-2026-10592, you should apply the available patch for wolfSSL.
3
What does CVE-2026-10592 affect?
CVE-2026-10592 impacts certificates with wildcard DNS SANs that can bypass CA name-constraint checks.
4
What are the consequences of CVE-2026-10592?
The vulnerability allows a certificate that should be rejected to be accepted, potentially leading to security risks.
5
When was CVE-2026-10592 published?
CVE-2026-10592 was published on June 25, 2026.