Back

MEDIUM

Subject CN name-constraint check bypassed when non-DNS SAN present

Published Sep 27, 2026

Description

A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN dNSName name-constraint check. The CN-as-DNS fallback was gated on cert->subjectCN != NULL && cert->altNames == NULL && !cert->isCA instead of "no dNSName SAN", so an out-of-scope CN was accepted. This incomplete fix from CVE-2026-6731, leading to the name-constraint check issue, was introduced in wolfSSL version 5.9.2.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner wolfSSL
Published Sep 27, 2026
Updated Sep 29, 2026
Reserved Sep 10, 2026
CISA Vulnrichment
Updated Sep 29, 2026
NVD
Status Analyzed
Modified Oct 2, 2026
Red Hat
Severity n/a
Public date n/a