AI analysis
wolfSSL versions 5.9.2 and earlier contain a CWE-295 certificate validation flaw in which the chain-walking state machine resets its validation state whenever it encounters an intermediate CA that carries no NameConstraints extension, discarding the restrictions imposed by a name-constrained CA higher in the chain. An attacker who controls or holds a CA certificate beneath a name-constrained intermediate can therefore present a chain that includes an unconstrained intermediate and have wolfSSL accept a certificate for hostnames outside the permitted namespace. The practical effect is that wolfSSL-based TLS clients and servers accept certificates they should reject, defeating name-based cryptographic delegation controls and enabling server impersonation or man-in-the-middle interception in deployments that rely on NameConstraints. The flaw exists in the default build configuration whenever name-constrained certificates are in use, so it primarily threatens embedded, IoT, and industrial products that bundle the library, and exploitation requires high attack complexity plus a PKI that actually uses name constraints (CVSS 4.0: 6.3, medium). No public proof of concept is known, there are no reports of exploitation in the wild, and the issue is not on CISA's KEV list; a fix is available in releases after 5.9.2, with 5.9.4 remediating this among other TLS flaws.
What to do: Upgrade to a wolfSSL release later than 5.9.2 — the current 5.9.4 release remediates this among 11 fixed TLS issues. If patching is not immediately possible, audit your PKI: deployments that never use NameConstraints extensions in any chain are not exposed to this specific bypass, but any chain where a name-constrained CA delegates through unconstrained intermediates is. Embedded and IoT product teams should also request updated firmware from vendors that bundle wolfSSL and verify the fix by testing chains that mix constrained and unconstrained intermediate CAs.
Affected
| wolfSSL Inc. wolfSSL (embedded TLS/SSL library) | 5.9.2 and earlier |
Estimated exposure
Unknown; wolfSSL's overall embedded footprint is estimated in the millions of devices (vendor marketing claims even billions), but the actually vulnerable… — wolfSSL is a library statically embedded in firmware and applications rather than a distinct internet-exposed service, so public scans and install counts cannot identify affected builds, and the additional requirement that the deployment…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforce NameConstraints extensions when there is an unconstrained CA tier between a name-constrained intermediate CA and the leaf certificate. wolfSSL incorrectly accepted certificates for hostnames they shouldn't be allowed to cover, due to a chain-walking state-machine bug that resets the validation state when encountering an intermediate without NameConstraints, thereby bypassing cryptographic delegation controls. This defect exists in the default build configuration that makes use of certificates where name constraint extensions are used. Thanks to Jack Lloyd, PathDiff, and Ben Smyth for reporting the issue.