TL;DR
wolfSSL shipped version 5.9.4 on September 25, 2026, fixing 10 wolfSSL vulnerabilities. Three are rated High, and each lets a malicious peer bypass TLS authentication or forge certificates in certain builds. Several flaws were found through the Anthropic OSS program.
- Total: 10 CVEs
- Severity: 3 High · 4 Medium · 3 Low
- Actively exploited: None confirmed
- Highest severity: 8.3 (High · CVSSv4) — CVE-2026-93302
- Action: Apply the latest security updates now
See a CVE's exploit risk spike before it becomes a headline.
Get EPSS spike alertsNotable CVEs
| CVE | CVSS (CVSSv4) | Type | Status |
|---|---|---|---|
| CVE-2026-93302 | 8.3 | Trusted peer certificate match ignores public key, allowing forged CA clones | Not exploited |
| CVE-2026-89102 | 8.3 | OCSP stapling v2 multi accepts non-CA chain certificates as issuers | Not exploited |
| CVE-2026-89136 | 8.3 | Client accepts unsolicited RawPublicKey server certificate type | Not exploited |
| CVE-2026-93304 | 6.3 | (D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange | Not exploited |
| CVE-2026-89133 | 6.3 | NameConstraints not enforced across unconstrained intermediate CA | Not exploited |
| CVE-2026-89134 | 6.3 | Subject CN name-constraint check bypassed when non-DNS SAN present | Not exploited |
| CVE-2026-89135 | 6.3 | Failed X509_verify_cert leaves unverified CA in shared CertManager | Not exploited |
| CVE-2026-15442 | 2.3 | Heap use-after-free on read during bidirectional (D)TLS shutdown | Not exploited |
Why These wolfSSL Vulnerabilities Matter
wolfSSL is a lightweight TLS library built for embedded systems, IoT devices, and cloud software. It often ships inside firmware, where updates arrive slowly. It also plugs into popular projects such as nginx, HAProxy, stunnel, and OpenVPN through compatibility builds.
Most of these bugs strike certificate checks. When those checks fail, an attacker can pose as a trusted server or client. That undercuts the whole point of TLS.
How the Attacks Work
CVE-2026-93302: Trusted Peer Check Ignores the Key
The MatchTrustedPeer function did not compare the public key. As a result, a forged clone of a trusted CA could pass verification. The flaw affects builds with WOLFSSL_TRUST_PEER_CERT that load CAs through the trusted-peer APIs. Builds that also define OPENSSL_COMPATIBLE_DEFAULTS widen the exposure to all CA loading. Autoconf builds for nginx, HAProxy, Apache httpd, and similar targets define both macros. Strix lists a CVSS score of 8.3. The Anthropic OSS program found it.
CVE-2026-89102: OCSP Multi-Stapling Certificate Forgery
This bug sits in the client’s RFC 6961 multiple OCSP stapling code. When enabled, the client treated any certificate in the peer’s chain as a certificate authority. So an attacker holding any certificate that chains to a trusted CA could forge certificates for other identities. The forged server certificate could also persist in the trust store for later connections.
CVE-2026-89136: Raw Public Key Authentication Bypass
With Raw Public Key (RPK) support enabled, a client could accept an unsolicited raw key from the server. That let a malicious server skip certificate authentication. RPK is off by default. Strix also rates this flaw CVSS 8.3.
Medium and Low Severity Fixes
The release also patches four Medium flaws. CVE-2026-93304 lets an early ChangeCipherSpec message trick TLS 1.2 and DTLS 1.2 clients. CVE-2026-89133 and CVE-2026-89134 break name-constraint checks. CVE-2026-89135 can plant an unverified CA in a shared certificate store. Three Low flaws round out the list: a use-after-free during shutdown (CVE-2026-15442), a skipped CRL check (CVE-2026-94417), and a hidden signature error under a memory-saving mode (CVE-2026-94418).
Affected Versions and Exploitation Status
Affected ranges vary by flaw. CVE-2026-93302 affects 5.3.0 through 5.9.2. CVE-2026-89102 affects 5.7.2 through 5.9.2. CVE-2026-89136 affects 5.6.0 through 5.9.2. Many issues only apply to specific build flags. The release notes do not report any exploitation in the wild, and no public proof-of-concept has been confirmed.
Patch and Mitigation Steps
Upgrade to wolfSSL 5.9.4. You can read the full fix list in the wolfSSL 5.9.4 release notes on GitHub. Packages are also on the official wolfSSL download page.
If you cannot upgrade yet, review your build flags. For CVE-2026-93302, wolfSSL suggests building with –disable-openssl-compatible-defaults and avoiding the trusted-peer APIs for CA loading. For CVE-2026-94417, tear down the affected WOLFSSL_CTX after patching, since a bad intermediate can stay trusted in long-running processes. Device makers should ship the fixes for these wolfSSL vulnerabilities in firmware updates quickly.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!