Critical flaw in wolfSSL library enables forged certificate use
ID: f3ccca43-8b27-58ff-915a-dcbe16d69c59
STIX ID: report--f3ccca43-8b27-58ff-915a-dcbe16d69c59
Feed Name: Bleeping Computer
Threat Score
A critical cryptographic validation vulnerability (CVE-2026-5194) was discovered in the wolfSSL TLS/SSL library that can accept undersized or improper digests when verifying signatures (including ECDSA, DSA, Ed25519/Ed448 and related algorithms), enabling attackers to present forged certificates and impersonate servers or connections; wolfSSL released a fix in version 5.9.1 and affected parties are advised to update and check downstream vendor packages and firmware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
