CVE-2026-89102

Source
https://cve.org/CVERecord?id=CVE-2026-89102
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89102.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89102
Downstream
Published
2026-09-27T09:22:42Z
Modified
2026-09-28T03:48:31Z
Severity
  • 8.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OCSP stapling v2 multi accepts non-CA chain certificates as issuers
Details

In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery. When a wolfSSL client enables OCSP stapling with the HAVE_CERTIFICATE_STATUS_REQUEST_V2 feature and calls wolfSSL_UseOCSPStaplingV2(ssl, WOLFSSL_CSR2_OCSP_MULTI, options), the client accepts any certificate in the peer's chain as a certificate authority without verifying that the certificate is actually authorized to act as one. This means that an attacker who possesses any certificate that chains to a CA trusted by the client (along with its private key) can forge certificates for arbitrary identities that will be accepted as valid by the client. The end entity certificate of the server is stored in the persistent trust store, affecting subsequent connections that reuse the context even when OCSP multi usage is not employed. Found by internal wolfSSL testing.

Database specific
{
    "cna_assigner":  "wolfSSL",
    "cwe_ids":  [
        "CWE-295"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89102.json"
}
References

Affected packages

Git / github.com/wolfssl/wolfssl

Affected ranges

Type
GIT
Repo
https://github.com/wolfssl/wolfssl
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "5.7.2"
        },
        {
            "last_affected":  "5.9.2"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v5.*
v5.2.1
v5.7.2-stable
v5.7.4-stable
v5.7.6-stable
v5.8.0-stable
v5.8.2-stable
v5.8.4-stable
v5.9.0-stable
v5.9.1-stable
v5.9.2-stable
Other
wolfEntropy2d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89102.json"