CVE-2026-11310Patch(wolfssl / wolfssl)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch wolfssl wolfssl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra (OPENSSL_EXTRA) and whose application validates certificates by calling X509_verify_cert() with caller-supplied untrusted intermediate certificates; for those users it is critical, otherwise the library is unaffected. In particular, native wolfSSL TLS/DTLS usage is not impacted. wolfSSL's X509_verify_cert() temporarily loads each caller-supplied untrusted intermediate into the certificate manager but failed to drop them before the trusted-store check, so an untrusted intermediate could anchor the path itself. An attacker can present a chain that never reaches a configured trust anchor and have it accepted, resulting in acceptance of an attacker-controlled certificate. This is certificate verification independent of TLS (e.g. S/MIME/CMS, code/firmware signing, JWT/JWS x5c), is not specific to any key type or algorithm, and a single untrusted intermediate suffices. The default wolfSSL TLS handshake (WOLFSSL_VERIFY_PEER) is not affected; only TLS applications doing manual or deferred peer verification through this API are, which also requires --enable-sessioncerts.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wolfssl

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-06-30); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
wolfssl

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-30: 1Mentions · 2026-07-08: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-06-30: 106-3007-08
Signal classification1 categories
Patch
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • iototsecnews@iototsecnews
    Patch

    WolfSSL の複数の脆弱性が FIX:TLS の信頼メカニズが損なわれる https://iototsecnews.jp/2026/06/30/multiple-wolfssl-vulnerabilities-expose-billions-of-servers-and-iot-devices-to-cyberattacks/ 多くのネットワーク機器や組み込みシステムで通信を守っている、暗号化ライブラリの安全性が脅かされる事態が起きています。具体的には CVE-2026-11310 などの脆弱性により、通信の暗号化や身元確認の仕組みが破られ、悪意の通信の許可やシステムの強制終了といった危険が生じます。管理するシステムを守るためには、開発元から提供されている修正済みの最新バージョンへの、速やかな更新が最善の対策です。また、使用していない不要な拡張機能を無効化することも効果的です。安全な通信環境を維持するために、まずは運用の環境を確認してみましょう。 #CVE202611310 #CVE202611999 #CVE20265194 #CVE20265264 #CVE20265295 #CVE20266679 #Vulnerability #wolfSSL

    Post summary

    The article reports multiple WolfSSL vulnerabilities that undermine TLS trust and urges users to apply vendor patches and disable unused extensions to mitigate potential risks.

    02000147
    500 followersView on X
  • TECHEPAGES@techepages
    Patch

    Multiple wolfSSL vulnerabilities expose billions of servers and IoT devices to cyberattacks 🔹 Flaws in wolfSSL's certificate verifier (CVE-2026-11310, CVE-2026-11999) allow attacker-controlled certificates to be wrongly trusted 🔹 Crafted DTLS 1.3 ACK messages can trigger heap buffer overflows, risking remote crashes or code execution (CVE-2026-6679, CVE-2026-5264) 🔹 Admins urged to upgrade to wolfSSL 5.9.1 or 5.9.2 and disable unneeded features like OpenSSL compatibility and PKCS7 support

    Post summary

    The post details multiple wolfSSL flaws that could allow certificate abuse and heap overflows, and it recommends upgrading to version 5.9.1/5.9.2 and disabling unnecessary features to mitigate risk.

    0000039
    22 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwolfsslwolfssl---

Explore more