CVE-2026-5501Disclosure(wolfssl / wolfssl)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch wolfssl wolfssl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker supplies an untrusted intermediate with Basic Constraints `CA:FALSE` that is legitimately signed by a trusted root. An attacker who obtains any leaf certificate from a trusted CA (e.g. a free DV cert from Let's Encrypt) can forge a certificate for any subject name with any public key and arbitrary signature bytes, and the function returns `WOLFSSL_SUCCESS` / `X509_V_OK`. The native wolfSSL TLS handshake path (`ProcessPeerCerts`) is not susceptible and the issue is limited to applications using the OpenSSL compatibility API directly, which would include integrations of wolfSSL into nginx and haproxy.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wolfssl

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-10); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
wolfssl

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-10: 3Mentions · 2026-04-11: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-10: 2Technical Details · 2026-04-11: 104-1004-11
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-103
Disclosure2General1
2026-04-111
General1
Full discourse4 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5501 📊 Severity: 8.6 🚨 Risk Level: High 🧩 Affects: Nginx Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5501 #CVE-2026-5501 #CVE #High #Nginx #CyberSecurity #InfoSec https://t.co/yf8BHSIs3y

    Post summary

    The tweet announces CVE‑2026‑5501 for Nginx with a severity of 8.6 and high risk, offering only a reference to the NVD entry without additional technical or exploitation details.

    0000050
    125 followersView on X
  • ANONHAVEN@anonhaven_com
    Disclosure

    A certificate validation bypass in wolfSSL's OpenSSL compatibility layer lets anyone holding a free Let's Encrypt cert forge a TLS chain for any domain. CVE-2026-5501 (CVSS 4.0 score 8.6) affects nginx and haproxy builds linked against wolfSSL. Patched in 5.9.1, one of six fixes from a single audit. Source: https://anonhaven.com/en/news/wolfssl-x509-ca-false-bypass-cve-2026-5501/ #InfoSec #CyberSecurity

    Post summary

    The article announces a certificate validation bypass in wolfSSL’s OpenSSL compatibility layer (CVE‑2026‑5501, CVSS 8.6), affecting nginx and haproxy, and notes the vulnerability is patched in version 5.9.1.

    0000083
    13 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5501 wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker supplies an untrus… https://www.cve.org/CVERecord?id=CVE-2026-5501

    Post summary

    The post announces CVE-2026-5501, noting that wolfSSL’s X509 verification in the OpenSSL compatibility layer fails to check the leaf signature in certain certificate chains, indicating a potential trust issue.

    00000106
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-5501 Certificate Signature Verification Bypass in wolfSSL OpenSSL Compatibility Layer https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5501

    Post summary

    The snippet merely announces CVE-2026-5501 with minimal information and no supporting details.

    0000056
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwolfsslwolfssl---

Explore more