HIGH
URI nameConstraints not enforced in ConfirmNameConstraints()
Published Apr 9, 2026
7.0
HIGHCVSS 4.0
EPSS 0.25%
Description
URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that violate the nameConstraints of the issuing CA, and wolfSSL would accept them as valid.
Affected products
-
- Version 0StatusaffectedConstraints<5.9.1
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-21178 Advisory
- https://github.com/wolfSSL/wolfssl/pull/10048 Issue TrackingPatch
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2026-2410
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-21178 | Advisory | |
| https://github.com/wolfSSL/wolfssl/pull/10048 | Issue TrackingPatch | |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2026-2410 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner wolfSSL
Published Apr 9, 2026
Updated Jul 2, 2026
Reserved Mar 31, 2026
Link CVE-2026-5263
CISA Vulnrichment
Updated Apr 10, 2026
ENISA EUVD
EUVD-2026-21178 Assigner wolfSSL
Published Apr 9, 2026
Updated Jul 2, 2026
Exploited since n/a
Link EUVD-2026-21178