Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-5263

Опубликовано: 09 апр. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that violate the nameConstraints of the issuing CA, and wolfSSL would accept them as valid.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*
Версия до 5.9.1 (исключая)

EPSS

Процентиль: 7%
0.00172
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 месяца назад

URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that violate the nameConstraints of the issuing CA, and wolfSSL would accept them as valid.

msrc
4 месяца назад

URI nameConstraints not enforced in ConfirmNameConstraints()

CVSS3: 6.5
debian
4 месяца назад

URI nameConstraints from constrained intermediate CAs are parsed but n ...

CVSS3: 6.5
github
4 месяца назад

URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that violate the nameConstraints of the issuing CA, and wolfSSL would accept them as valid.

EPSS

Процентиль: 7%
0.00172
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-295