CVE-2026-89135: Failed X509_verify_cert leaves unverified CA in shared CertManager
A failed X509verifycert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certificate validation in every type-blind sibling consumer (native TLS, OCSP, CRL, direct CM verify). This affects version 5.8.4 through 5.9.2 of wolfSSL with the macros (OPENSSLEXTRA && !NOCERTS && !WOLFCRYPTONLY) defined or built with --enable-opensslextra and the application is specifically making calls to the X509verifycert function.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments use wolfSSL versions 5.8.4 through 5.9.2 with OPENSSL_EXTRA enabled while NO_CERTS and WOLFCRYPT_ONLY are not defined, or are built with --enable-opensslextra. The application must also specifically call X509_verify_cert.
What must an attacker achieve to exploit this issue?
An attacker must cause X509_verify_cert to fail in a way that introduces an unverified attacker-controlled CA into the shared CertManager. That CA can then bypass certificate validation in type-blind sibling consumers using the same shared CertManager.
Which certificate-validation paths can be affected after a failed verification?
The described impact includes native TLS, OCSP, CRL, and direct certificate-manager verification. These paths are affected when they are type-blind sibling consumers of the shared CertManager.