CVE-2026-89133
Last modified
CVE-2026-89133 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforce NameConstraints extensions when there is an unconstrained CA tier between a name-constrained intermediate CA and the leaf certificate. wolfSSL incorrectly accepted certificates for hostnames they shouldn't be allowed to cover, due to a chain-walking state-machine bug that resets the validation state when encountering an intermediate without NameConstraints, thereby bypassing cryptographic delegation controls.
Description
wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforce NameConstraints extensions when there is an unconstrained CA tier between a name-constrained intermediate CA and the leaf certificate. wolfSSL incorrectly accepted certificates for hostnames they shouldn't be allowed to cover, due to a chain-walking state-machine bug that resets the validation state when encountering an intermediate without NameConstraints, thereby bypassing cryptographic delegation controls. This defect exists in the default build configuration that makes use of certificates where name constraint extensions are used. Thanks to Jack Lloyd, PathDiff, and Ben Smyth for reporting the issue.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| wolfSSL | wolfSSL | <= 5.9.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-89133?
How severe is CVE-2026-89133?
How do I fix CVE-2026-89133?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-89099A race condition in the document value layer of MongoDB Serv…7.5
- CVE-2026-8910The WP Emoticon Rating plugin for WordPress is vulnerable to…6.1
- CVE-2026-89102In wolfSSL versions 5.7.2 through 5.9.2 there is a client-si…8.3
- CVE-2026-8911The WP AutoBuzz plugin for WordPress is vulnerable to Cross-…6.1
- CVE-2026-8912The Contest Gallery plugin for WordPress is vulnerable to SQ…7.5
- CVE-2026-8913A command Injection vulnerability exists in the WireGuard cl…8.5
- CVE-2026-89134A certificate with no dNSName SAN but another SAN type prese…6.3
- CVE-2026-89135A failed X509_verify_cert call permanently plants an unverif…6.3
- CVE-2026-89136When using RPK (Raw Public Key), the client side of a TLS 1.…8.3
- CVE-2026-89138The Filter Gallery plugin for WordPress is vulnerable to aut…4.3
- CVE-2026-89139Temporal Server compiles a Worker Controller Instance module…8.7
- CVE-2026-8914In Teltonika Networks RUTOS devices, running versions 7.22 t…8.4
Are you affected by CVE-2026-89133?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
