logo

Critical flaw in wolfSSL library enables forged certificate use

ID: f3ccca43-8b27-58ff-915a-dcbe16d69c59

STIX ID: report--f3ccca43-8b27-58ff-915a-dcbe16d69c59

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-04-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical cryptographic validation vulnerability (CVE-2026-5194) was discovered in the wolfSSL TLS/SSL library that can accept undersized or improper digests when verifying signatures (including ECDSA, DSA, Ed25519/Ed448 and related algorithms), enabling attackers to present forged certificates and impersonate servers or connections; wolfSSL released a fix in version 5.9.1 and affected parties are advised to update and check downstream vendor packages and firmware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.