Critical updates have been released addressing multiple security flaws within the wolfSSL library up to version 5.9.2, which impact secure communications across embedded systems, IoT devices, and various cloud software integrations. The newly available version 5.9.4 remediates a total of ten distinct vulnerabilities, including three high-severity issues that allow malicious peers to bypass TLS authentication or forge certificates under specific build configurations. These cryptographic implementation bugs undermine core trust verification mechanisms, presenting significant interception and impersonation risks for dependent services. While no active exploitation has been confirmed in the wild, immediate remediation is strongly advised to prevent potential credential theft or man-in-the-middle attacks.
CVE-2026-93302:The trusted peer verification function fails to properly validate public keys during certificate matching, allowing a forged clone of a trusted certificate authority to pass validation. This vulnerability affects software builds utilizing specific trust-peer APIs and compatibility flags commonly enabled in web server and proxy integrations. An attacker capable of positioning themselves in the communication path can exploit this flaw to present fraudulent server credentials. The resulting impact compromises end-to-end transport layer security and permits unauthorized session decryption.[/subscribe_to_unlock_form]
Critical updates have been released addressing multiple security flaws within the wolfSSL library up to version 5.9.2, which impact secure communications across embedded systems, IoT devices, and various cloud software integrations. The newly available version 5.9.4 remediates a total of ten distinct vulnerabilities, including three high-severity issues that allow malicious peers to bypass TLS authentication or forge certificates under specific build configurations. These cryptographic implementation bugs undermine core trust verification mechanisms, presenting significant interception and impersonation risks for dependent services. While no active exploitation has been confirmed in the wild, immediate remediation is strongly advised to prevent potential credential theft or man-in-the-middle attacks.
CVE-2026-93302:The trusted peer verification function fails to properly validate public keys during certificate matching, allowing a forged clone of a trusted certificate authority to pass validation. This vulnerability affects software builds utilizing specific trust-peer APIs and compatibility flags commonly enabled in web server and proxy integrations. An attacker capable of positioning themselves in the communication path can exploit this flaw to present fraudulent server credentials. The resulting impact compromises end-to-end transport layer security and permits unauthorized session decryption.[emaillocker id="1283"]
CVE-2026-89102:Improper validation handling within the client multi-stapling code permits non-authority chain certificates to be incorrectly trusted as legitimate issuers during connection handshakes. This implementation error allows malicious entities holding certificates linked to a trusted authority to generate unauthorized identities. The forged credentials can further persist within local trust stores, affecting subsequent connection attempts. Successful exploitation enables seamless peer impersonation and bypasses standard validation controls.
CVE-2026-89136:Support for raw public key authentication can be leveraged by a malicious peer to bypass mandatory certificate validation checks through unsolicited key presentations. The flaw permits clients to improperly accept raw public keys when not explicitly required by the active session configuration. An attacker can exploit this condition to establish authenticated connections without possessing valid cryptographic certificates. The primary risk involves unauthorized service access and complete cryptographic bypass in affected builds.
CVE-2026-93304:Transport layer security implementations incorrectly accept premature early change cipher spec messages within specific protocol versions. This behavior disrupts the expected handshake sequence and can mislead client state machines during connection setup. The associated exploitation risk involves potential synchronization attacks or protocol state confusion. Affected deployments should incorporate state validation checks to ensure strict protocol adherence.
CVE-2026-89133:Name constraint verification logic fails to enforce proper domain restrictions across unconstrained intermediate certificate authorities. This flaw permits subordinate entities to issue valid certificates for out-of-scope domains without triggering security warnings. An attacker can leverage this oversight to generate fraudulent domain credentials for arbitrary targets. The risk profile centers on widespread spoofing capabilities across enterprise infrastructure.
CVE-2026-89134:Subject common name constraints are improperly bypassed when non-DNS subject alternative names are present during validation evaluations. The parsing discrepancy allows invalid certificates to satisfy hostname verification routines incorrectly. Exploitation requires an attacker to supply specially crafted alternative names during the handshake process. Successful attacks result in improper domain validation and potential session interception.
CVE-2026-89135:Failed certificate verification routines leave unverified authority structures resident within shared certificate manager components. Subsequent connection attempts can inadvertently inherit and trust these unverified components during path building. This flaw introduces persistent validation risks in long-running processes utilizing shared credential caches. Remediation requires ensuring strict cleanup of failed validation chains.
CVE-2026-15442:A heap use-after-free condition occurs during read operations executed as part of bidirectional protocol shutdown procedures. Improper memory management following connection termination creates potential instability within affected runtime environments. While exploitation for arbitrary code execution remains difficult, repeated triggering can cause service denial conditions. Proper memory lifecycle enforcement eliminates this vulnerability.
Addressing these vulnerabilities requires prompt coordination across engineering and security teams to safeguard dependent network services. Comprehensive mitigation involves upgrading all affected software packages to the latest stable release version.
We recommend you to update wolfSSL to version 5.9.4.
The following reports contain further technical details:
[/emaillocker]