CVE-2026-6731: X.509 name constraint bypass via Subject CN treated as a DNS name
Published Jun 25, 2026
·Updated
X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS name constraints could be accepted.
Affected Software
1 affected component
wolfSSL wolfssl>=3.9.10<5.9.2
Remediation
Patch Available
Event History
Jun 25, 2026
CVE Published
via MITRE·08:08 PM
Data Sourced
via MITRE·08:08 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-6731?
CVE-2026-6731 has a medium severity rating of 6 according to the CVSS score.
2
How do I fix CVE-2026-6731?
To mitigate CVE-2026-6731, a patch is available and should be applied to update the wolfSSL software.
3
What does CVE-2026-6731 affect?
CVE-2026-6731 affects the wolfSSL library, specifically related to X.509 name constraints when using Subject Common Name.
4
What is the risk level associated with CVE-2026-6731?
CVE-2026-6731 has been assigned a risk score of 43, indicating a significant potential impact.
5
What is the main issue with CVE-2026-6731?
The main issue with CVE-2026-6731 is that it allows for name constraint bypass via the Subject Common Name being accepted as a DNS name.