CVE-2026-6412: Continued acceptance of SHA-1/MD5 digests in certificate processing
Published Jun 25, 2026
·Updated
Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate processing.
Affected Software
1 affected component
wolfSSL wolfssl>=3.9.10<5.9.2
Remediation
Patch Available
Event History
Jun 25, 2026
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-6412?
CVE-2026-6412 has a severity rating of low with a CVSS score of 4.0.
2
How do I fix CVE-2026-6412?
You can fix CVE-2026-6412 by applying the latest patch available for wolfSSL.
3
What does CVE-2026-6412 affect?
CVE-2026-6412 affects the certificate processing in wolfSSL due to the continued acceptance of SHA-1 and MD5 digests.
4
Is there a workaround for CVE-2026-6412?
No specific workaround is mentioned for CVE-2026-6412; patching is recommended.
5
When was CVE-2026-6412 published?
CVE-2026-6412 was published on June 25, 2026.