Junglewise Threat Intelligence

CVE-2026-6412: wolfSSL Use of Broken Cryptography in Certificate Processing

CVE-2026-6412 · Severity: info · CVSS 2.3 · Published 2026-06-25

Technologies: Wolfssl. Vendors: Wolfssl.

Executive brief

wolfSSL is a security library used to protect communications for embedded devices and cloud services. A policy compliance issue was identified where the library continued to accept older, insecure cryptographic methods (SHA-1 and MD5) during the verification of digital certificates. While this is primarily a compliance concern, it could theoretically allow for the use of weak certificates that do not meet modern security standards.

Technical details

wolfSSL versions 3.9.10 through 5.9.1 were found to be non-compliant with RFC 8446 due to the continued acceptance of MD5 and SHA-1 hashes during certificate chain verification. The vulnerability (CWE-327) stems from a lack of enforcement guards in the certificate processing logic, specifically within the HashForSignature() function. An attacker could potentially present certificates signed with these broken algorithms to bypass modern policy requirements. The fix introduces a verify-mode guard that rejects MD5-signed certificates by default unless the WOLFSSL_ALLOW_MD5_CERT_SIGS macro is explicitly defined. This issue was addressed in wolfSSL version 5.9.1.

Affected products

  • wolfSSL wolfSSL 3.9.10 through 5.9.1

Timeline

  • 2026-04-15: patched: Pull request merged into master branch
  • 2026-06-25: disclosed: CVE published to NVD

References

Related threats