URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that violate the nameConstraints of the issuing CA, and wolfSSL would accept them as valid.
References
| Link | Resource |
|---|---|
| https://github.com/wolfSSL/wolfssl/pull/10048 | Issue Tracking Patch |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2026-2410 |
Configurations
History
No history.
Information
Published : 2026-04-09 22:16
Updated : 2026-07-02 15:17
NVD link : CVE-2026-5263
Mitre link : CVE-2026-5263
CVE.ORG link : CVE-2026-5263
JSON object : View
Products Affected
wolfssl
- wolfssl
CWE
CWE-295
Improper Certificate Validation
