CVE-2026-89135

⚪ Do wiadomości

Błąd w wolfSSL pozwala na trwałe zainstalowanie niezweryfikowanego CA, omijając walidację certyfikatów.

CVSS
6.5
EPSS
0.1%
Exploit
none
Vendor
wolfssl
Opis źródłowy (NVD)

A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certificate validation in every type-blind sibling consumer (native TLS, OCSP, CRL, direct CM verify). This affects version 5.8.4 through 5.9.2 of wolfSSL with the macros (OPENSSL_EXTRA && !NO_CERTS && !WOLFCRYPT_ONLY) defined or built with --enable-opensslextra and the application is specifically making calls to the X509_verify_cert function.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.1%
Opublikowano (NVD)2026-09-27 10:16:59 UTC
Ostatnia modyfikacja (NVD)2026-10-02 18:57:29 UTC
Referencje