wolfSSL 5.9.4 Patches 11 Security Flaws Affecting TLS and Certificate Validation
wolfSSL 5.9.4 fixes 11 TLS and certificate-validation flaws, including trusted-peer and OCSP authentication bypasses.
wolfSSL 5.9.4 fixes 11 flaws in TLS and DTLS handshakes, X.509 validation, OCSP stapling, session resumption, and memory safety. CVE-2026-93302, affecting 5.3.0 through 5.9.2, can let a forged CA clone pass trusted-peer checks when WOLFSSL_TRUST_PEER_CERT is enabled. High-severity CVE-2026-89102 and CVE-2026-89136 may bypass authentication in multi-OCSP and Raw Public Key builds. Other fixes include ChangeCipherSpec ordering, NameConstraints bypasses, skipped CRL checks, session-cache poisoning, and a heap use-after-free. No exploitation is reported.