CVE-2026-89135
Failed X509_verify_cert leaves unverified CA in shared CertManager
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certificate validation in every type-blind sibling consumer (native TLS, OCSP, CRL, direct CM verify). This affects version 5.8.4 through 5.9.2 of wolfSSL with the macros (OPENSSL_EXTRA && !NO_CERTS && !WOLFCRYPT_ONLY) defined or built with --enable-opensslextra and the application is specifically making calls to the X509_verify_cert function.
| CWE | CWE-295 |
| Vendor | wolfssl |
| Product | wolfssl |
| Published | Sep 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for wolfssl wolfssl
Be the first to know when new unknown vulnerabilities affecting wolfssl wolfssl are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
wolfSSL / wolfSSL
5.8.4 โค 5.9.2
References
Credits
Christos Papakonstantinou (Cantina Security)