Junglewise Threat Intelligence

CVE-2026-11310: wolfSSL X.509 trust-chain bypass in OpenSSL compatibility layer

CVE-2026-11310 · Severity: info · CVSS 8.7 · Published 2026-06-25

Technologies: Wolfssl. Vendors: Wolfssl.

Executive brief

wolfSSL is a security library used to encrypt communications and verify digital signatures. A flaw in its certificate verification process allows an attacker to present a fraudulent digital certificate that the software will incorrectly trust. This could allow an attacker to impersonate legitimate services, bypass code-signing protections, or intercept sensitive data in applications that use specific OpenSSL-compatibility features.

Technical details

A vulnerability exists in the wolfSSL_X509_verify_cert() function within the OpenSSL compatibility layer. The function temporarily loads caller-supplied untrusted intermediate certificates into the certificate manager but fails to remove them before performing the trusted-store check. Consequently, an attacker can provide a certificate chain where an untrusted intermediate certificate anchors the path, bypassing the requirement to reach a configured root CA. This affects builds with --enable-opensslextra where applications perform manual certificate validation (e.g., for S/MIME, firmware signing, or JWTs). Standard TLS/DTLS handshakes using WOLFSSL_VERIFY_PEER are not impacted. The issue is addressed in wolfSSL version 5.9.2.

Affected products

  • wolfSSL wolfSSL 5.8.4 to 5.9.1

Timeline

  • 2026-06-12: patched: Fix merged in GitHub pull request 10674
  • 2026-06-25: disclosed: CVE published and NVD entry created

References

Related threats