CVE-2026-95208: High severity wolfSSL wolfssl vulnerability
Published Oct 8, 2026
·Updated
An issue in the ConfirmNameConstraints() function (wolfcrypt/src/asn.c) of wolfSSL v5.9.1 and v5.9.2 allows attackers to cause a Denial of Service (DoS) via providing crafted Certificate Authority certificates, leading to valid certificates without SAN to be incorrectly rejected by wolfSSL-based TLS clients.
Affected Software
1 affected component
wolfSSL wolfssl=5.9.1, =5.9.2
Event History
Oct 8, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which wolfSSL versions are identified as affected?
The issue is identified in wolfSSL versions 5.9.1 and 5.9.2.
2
What does an attacker need to provide to trigger the issue?
An attacker needs to provide crafted Certificate Authority certificates to a wolfSSL-based TLS client.
3
What is the observable impact on affected TLS clients?
Affected clients can incorrectly reject otherwise valid certificates that do not contain a Subject Alternative Name (SAN), resulting in a denial of service.