CVE-2026-5263: URI nameConstraints not enforced in ConfirmNameConstraints()
Published Apr 9, 2026
·Updated
URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that violate the nameConstraints of the issuing CA, and wolfSSL would accept them as valid.
Affected Software
2 affected components
wolfSSL wolfCrypt
wolfSSL wolfssl<5.9.1
Remediation
Patch Available
Event History
Apr 9, 2026
CVE Published
via MITRE·09:15 PM
Data Sourced
via MITRE·09:15 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-5263?
CVE-2026-5263 has a severity rating of high with a CVSS score of 7.
2
How do I fix CVE-2026-5263?
To fix CVE-2026-5263, apply the available patch from the wolfSSL repository.
3
What is the impact of CVE-2026-5263?
The impact of CVE-2026-5263 allows a compromised sub-CA to issue invalid leaf certificates, potentially leading to unauthorized access.
4
Which software is affected by CVE-2026-5263?
CVE-2026-5263 affects wolfSSL and its wolfCrypt library.
5
When was CVE-2026-5263 published?
CVE-2026-5263 was published on April 9, 2026.