Junglewise Threat Intelligence

CVE-2026-5263: wolfSSL improper X.509 nameConstraints enforcement in wolfcrypt

CVE-2026-5263 · Severity: medium · CVSS 6.5 · Published 2026-04-09

Technologies: Wolfssl. Vendors: Wolfssl.

Executive brief

wolfSSL is a security library used by many Internet-of-Things (IoT) and embedded devices to establish secure connections. A flaw in how it verifies digital certificates allows a malicious or compromised certificate authority to issue unauthorized certificates that bypass security restrictions. This could allow an attacker to impersonate legitimate services or intercept encrypted communications.

Technical details

An improper certificate validation vulnerability exists in wolfSSL's ASN.1 parsing and certificate verification logic (specifically within `wolfcrypt/src/asn.c`). The `ConfirmNameConstraints` function fails to iterate over and validate URI and registeredID (RID) GeneralName types against the nameConstraints extension of intermediate CAs. Additionally, the `DecodeSubtree` function does not correctly store RID constraints, and the SAN parser may skip RID entries depending on build flags. This allows a compromised or malicious intermediate CA to issue leaf certificates with Subject Alternative Name (SAN) entries that exceed its permitted scope, leading to a bypass of the X.509 name constraint security mechanism. The issue is fixed in wolfSSL version 5.9.1.

Affected products

  • wolfSSL wolfSSL versions before 5.9.1

Timeline

  • 2026-03-31: patched: Fix merged in GitHub pull request 10048
  • 2026-04-09: disclosed: Initial CVE publication
  • 2026-07-02: advisory: Detailed Talos vulnerability report published

References

Related threats