๐Ÿ” CVE Alert

CVE-2026-89136

UNKNOWN 0.0

Client accepts unsolicited RawPublicKey server certificate type

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited server_cert_type=RawPublicKey which allowed a malicious or misbehaving server to bypass authentication. RPK is off by default and only enabled in --enable-rpk OR --enable-all OR --enable-distro AKA HAVE_RPK builds.

CWE CWE-287
Vendor wolfssl
Product wolfssl
Published Sep 27, 2026
Last Updated Sep 27, 2026
Stay Ahead of the Next One

Get instant alerts for wolfssl wolfssl

Be the first to know when new unknown vulnerabilities affecting wolfssl wolfssl are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

wolfSSL / wolfSSL
5.6.0 โ‰ค 5.9.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/wolfSSL/wolfssl/pull/11009

Credits

Christos Papakonstantinou (Cantina Security)