GPU VulnDB

Database/Kernel, userspace & hypervisor

wolfSSL: trusted-peer matching ignores the public key, so a forged CA clone verifies

CVSS 8.3CVE-2026-93302Kernel, userspace & hypervisorcurated

Impact

MatchTrustedPeer compares certificates without considering the public key, so a certificate that clones a loaded CA's identifying fields passes verification even though it carries an attacker's key. A malicious (D)TLS server can therefore bypass client authentication once it knows which CAs the client accepts, and the mirror case breaks mutual TLS where the client can learn the server's loaded CAs. Affected builds are those with WOLFSSL_TRUST_PEER_CERT that load CAs via wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert(); with OPENSSL_COMPATIBLE_DEFAULTS also defined the exposure widens to all CA loading, and wolfSSL notes both macros are set in autoconf builds such as nginx, haproxy, stunnel, wpa_supplicant, apache httpd, hitch, bind, rsyslog, ffmpeg and distro builds. Where wolfSSL backs mTLS between fleet components, that is an authentication bypass on links an operator believes are mutually authenticated.

Who can reach it

A network attacker able to act as the (D)TLS peer - typically an on-path or otherwise reachable server - who knows which CA certificates the victim loaded. No authentication needed (PR:N); the knowledge requirement is what makes attack requirements present (AT:P).

What to do

Update to the latest wolfSSL or apply the upstream fix commit (22bcd51), then rebuild and restart every service linked against it - a library update plus a restart of each dependent daemon, not a node reboot. If you cannot update, wolfSSL's own mitigation is to build with --disable-openssl-compatible-defaults and stop loading CAs through wolfSSL_CTX_trust_peer_cert()/wolfSSL_trust_peer_cert(). Note that distro-packaged nginx/haproxy/bind builds may need to be rebuilt, not just restarted.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.