Junglewise Threat Intelligence

CVE-2026-7532: wolfSSL IP address name constraints bypass when WOLFSSL_IP_ALT_NAME is undefined

CVE-2026-7532 · Severity: info · CVSS 5.7 · Published 2026-06-25

Technologies: Wolfssl. Vendors: Wolfssl.

Executive brief

wolfSSL is a security library used to protect communications for embedded devices and cloud services. A configuration issue was found where the library fails to enforce certain IP address restrictions on digital certificates if a specific setting (WOLFSSL_IP_ALT_NAME) is not enabled. This could allow a malicious or compromised certificate authority to issue certificates for unauthorized IP addresses, potentially leading to impersonation or unauthorized access within a restricted network.

Technical details

A vulnerability exists in wolfSSL's certificate validation logic (CWE-295) where iPAddress name constraints are not enforced if the WOLFSSL_IP_ALT_NAME macro is undefined. In this configuration, the library fails to parse and store iPAddress GeneralNames, causing the ConfirmNameConstraints function to skip enforcement of permitted or excluded subtrees for IP addresses. An attacker with the ability to influence certificate issuance from a constrained intermediate CA could bypass these restrictions. The issue was addressed by ensuring iPAddress and registeredID GeneralNames are parsed and stored unconditionally for constraint enforcement, regardless of whether human-readable string helpers are enabled. Fixes are available in versions following 5.9.1.

Affected products

  • wolfSSL wolfSSL <= 5.9.1

Timeline

  • 2026-04-29: other: Pull request submitted to fix the issue
  • 2026-05-08: patched: Fix merged into wolfSSL master branch
  • 2026-06-25: advisory: CVE-2026-7532 published

References

Related threats