OVERVIEW CVE-2026-5263 is a certificate validation bypass vulnerability in wolfSSL that affects the wolfcrypt library's ASN.1 parsing component. The flaw exists in how URI-based nameConstraints are handled during X.509 certificate chain verification. Specifically, intermediate certification authorities can issue leaf certificates with Subject Alternative Name (SAN) URI entries that violate the nameConstraints restrictions imposed by their issuing CA, and wolfSSL will incorrectly validate these malformed certificates as legitimate. SEVERITY This vulnerability requires a compromised or malicious subordinate CA to exploit, representing a moderate attack complexity scenario. The primary attack vector is network-based, leveraging fraudulent certificate issuance to bypass domain validation controls. The potential impact is significant for applications relying on nameConstraints as a security boundary, potentially allowing unauthorized entities to issue certificates for restricted namespaces. The CVSS score is not yet available, though the FAUCET risk score of 37.0/100 and near-zero EPSS percentile indicate this is viewed as a lower-priority threat relative to the broader vulnerability landscape. EXPLOITATION STATUS There is currently no evidence of active exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog, and no public exploit code is documented. Community attention remains minimal, consistent with the vulnerability's inactive status on security hotlists. Organizations using wolfSSL should apply patches when available as part of standard maintenance cycles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.9.1CPE matchmatch criteria | cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* | ||
>= 0, < 5.9.1CPE match | cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.