Back

HIGH

URI nameConstraints not enforced in ConfirmNameConstraints()

Published Apr 9, 2026

Description

URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that violate the nameConstraints of the issuing CA, and wolfSSL would accept them as valid.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner wolfSSL
Published Apr 9, 2026
Updated Jul 2, 2026
Reserved Mar 31, 2026
CISA Vulnrichment
Updated Apr 10, 2026
NVD
Status Modified
Modified Jul 2, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner wolfSSL
Published Apr 9, 2026
Updated Jul 2, 2026
Exploited since n/a
EUVD-2026-21178