CVE-2026-11310: X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring
X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSLX509verifycert()). This affects only builds with --enable-opensslextra (OPENSSLEXTRA) and whose application validates certificates by calling X509verifycert() with caller-supplied untrusted intermediate certificates; for those users it is critical, otherwise the library is unaffected. In particular, native wolfSSL TLS/DTLS usage is not impacted. wolfSSL's X509verifycert() temporarily loads each caller-supplied untrusted intermediate into the certificate manager but failed to drop them before the trusted-store check, so an untrusted intermediate could anchor the path itself. An attacker can present a chain that never reaches a configured trust anchor and have it accepted, resulting in acceptance of an attacker-controlled certificate. This is certificate verification independent of TLS (e.g. S/MIME/CMS, code/firmware signing, JWT/JWS x5c), is not specific to any key type or algorithm, and a single untrusted intermediate suffices. The default wolfSSL TLS handshake (WOLFSSLVERIFYPEER) is not affected; only TLS applications doing manual or deferred peer verification through this API are, which also requires --enable-sessioncerts.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11310?
CVE-2026-11310 has a high severity rating of 8.7.
How does CVE-2026-11310 affect wolfSSL?
CVE-2026-11310 affects wolfSSL's X.509 certificate verification, allowing for a trust-chain bypass when using untrusted intermediate certificates.
How do I fix CVE-2026-11310?
The fix for CVE-2026-11310 is to apply the available patch provided by wolfSSL.
Which builds are affected by CVE-2026-11310?
Only wolfSSL builds with the --enable-opensslextra option are affected by CVE-2026-11310.
What type of applications are at risk from CVE-2026-11310?
Applications that validate certificates by calling X509_verify_cert() with caller-supplied untrusted intermediate certificates are at risk from CVE-2026-11310.