Junglewise Threat Intelligence

CVE-2026-11999: wolfSSL certificate trust-chain bypass in OpenSSL compatibility layer

CVE-2026-11999 · Severity: info · CVSS 8.2 · Published 2026-06-25

Technologies: Wolfssl. Vendors: Wolfssl.

Executive brief

wolfSSL is a security library used to establish encrypted connections and verify digital certificates. A flaw in its certificate verification component allows an attacker to bypass security checks by providing an excessively long chain of certificates. This could allow an attacker to impersonate a trusted website or service, potentially leading to intercepted data or unauthorized access for applications using specific manual verification settings.

Technical details

A trust-chain bypass exists in the wolfSSL_X509_verify_cert() function within the OpenSSL compatibility layer. The vulnerability is caused by path-depth exhaustion; when a certificate chain exceeds the maximum path depth (default 100), the verifier returns success based on the last verified link rather than ensuring the chain terminates at a configured trust anchor. This allows an attacker to gain acceptance for an arbitrary certificate by providing a sufficiently deep chain of untrusted intermediates. This issue specifically affects builds with --enable-opensslextra where the application manually calls X509_verify_cert() with caller-supplied untrusted intermediates. Native TLS/DTLS handshakes using WOLFSSL_VERIFY_PEER are not affected. The issue is addressed in wolfSSL version 5.9.2.

Affected products

  • wolfSSL wolfSSL 5.7.4 to 5.9.1

Timeline

  • 2026-06-12: patched: Fix merged in pull request 10674
  • 2026-06-25: disclosed: CVE published

References

Related threats