CVE-2025-7395: wolfSSL
Critical severity, CVSS 9.2. EPSS: 0.3% chance of exploitation in the next 30 days.
A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.
Affected products
- wolfSSL wolfSSL: from 5.6.4, up to and including 5.8.0
Published 2025-07-18. Last modified 2026-06-17.