AI analysis
When an application turns on both OCSP and CRL checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips the CRL check for any peer certificate that has no Authority Information Access OCSP URL and accepts a certificate that the loaded CRL lists as revoked. A soft-fail for a missing responder is treated as success before the code decides whether the CRL fallback is still required, so "no OCSP URL" is indistinguishable from a "good" OCSP answer. An attacker who can present such a revoked certificate can complete TLS 1.0 through TLS 1.3 or DTLS as a client, or as a server under mutual or post-handshake authentication; if the skipped certificate is an intermediate, it is promoted to a trusted signer for later connections on that context until the WOLFSSL_CTX is destroyed. Only wolfSSL builds through 5.9.2 that define both HAVE_OCSP and HAVE_CRL and that actually enable both checks with a loaded CRL are affected; OCSP stapling alone is not, and on 5.9.1 and 5.9.2 WOLFSSL_OCSP_CHECKALL fails closed. No public proof of concept is known, and the issue is not listed in CISA KEV; CVSS 4.0 is 2.3 (low).
What to do: Upgrade wolfSSL to a release after 5.9.2 (the 5.9.4 announcement covers multiple TLS fixes) and then tear down and recreate every long-running WOLFSSL_CTX so a previously accepted revoked intermediate is not kept as a trusted signer. Until you upgrade, do not enable OCSP and CRL together on one context; on 5.9.1 and 5.9.2, WOLFSSL_OCSP_CHECKALL fails closed, and OCSP stapling alone is not this bug. Confirm both wolfSSL_CTX_EnableOCSP (or CertManager/EnableOCSP equivalents) and EnableCRL are in use with a CRL loaded before treating a deployment as exposed.
Affected
| wolfSSL | 5.9.2 and earlier, when built with both HAVE_OCSP and HAVE_CRL and the application enables both OCSP and CRL with a CRL loaded; on 5.9.1 and 5.9.2, WOLFSSL_OCSP |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips the CRL check for any peer certificate that carries no Authority Information Access OCSP URL, and accepts a certificate the loaded CRL lists as revoked. The soft-fail policy for a missing responder collapses the OCSP result onto success before the code decides whether the CRL fallback is still needed, so "no responder exists" becomes indistinguishable from "the responder answered good". Affected builds define both HAVE_OCSP and HAVE_CRL: --enable-ocsp --enable-crl directly, and implicitly --enable-all, --enable-distro, --enable-curl, --enable-nginx, --enable-haproxy, --enable-stunnel, --enable-lighty, --enable-wpas, --enable-strongswan, --enable-mosquitto, --enable-jni, --enable-openvpn and --enable-krb. An application is affected only if it calls both wolfSSL_CTX_EnableOCSP() (or wolfSSL_EnableOCSP() / wolfSSL_CertManagerEnableOCSP()) and wolfSSL_CTX_EnableCRL() (or the equivalents) with a CRL loaded; an application that uses OCSP stapling alone through wolfSSL_CTX_EnableOCSPStapling() is not affected, because that sets up a separate OCSP instance. The defect sits in ProcessPeerCerts() and is reachable over TLS 1.0 through TLS 1.3 and DTLS, both on a client verifying a server certificate and on a server verifying a client certificate under mutual or post-handshake authentication. When the skipped check falls on a chain certificate rather than the leaf, the unchecked intermediate is promoted into the certificate manager and stays a trusted signer for every later connection on that context, so an affected long-running process needs its WOLFSSL_CTX torn down and not only its library replaced. All wolfSSL versions from 5.9.2 and earlier are affected; on versions 5.9.1 and 5.9.2 the WOLFSSL_OCSP_CHECKALL configuration fails closed with OCSP_NEED_URL, which leaves wolfSSL_CTX_EnableOCSP() without CHECKALL as the exposed configuration on 5.9.2.