CVE-2026-95208
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
An issue in the ConfirmNameConstraints() function (wolfcrypt/src/asn.c) of wolfSSL v5.9.1 and v5.9.2 allows attackers to cause a Denial of Service (DoS) via providing crafted Certificate Authority certificates, leading to valid certificates without SAN to be incorrectly rejected by wolfSSL-based TLS clients.
Published 2026-10-08. Last modified 2026-10-08.