GHSA-gq94-hf88-g4wv
A vulnerability in TLS 1.3 post-handshake authentication (PHA) in wolfSSL allows a server to accept a client's Finished message without the client sending a Certificate and CertificateVerify when post-handshake authentication is enabled. This occurs because the exemption for an empty or absent peer certificate, intended only for the initial handshake, was incorrectly applied during post-handshake CertificateRequest. Only TLS 1.3 servers built with post-handshake authentication support and configured to request client certificates after the handshake are affected. Clients and servers not using post-handshake authentication are not impacted.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-55962) affects TLS 1.3 servers using wolfSSL with post-handshake authentication enabled (WOLFSSL_POST_HANDSHAKE_AUTH / --enable-postauth) and configured to verify client certificates post-handshake (WOLFSSL_VERIFY_POST_HANDSHAKE). The issue is that the server could accept a client's Finished message without the client having sent the required Certificate and CertificateVerify messages during post-handshake authentication. This happens because the exemption allowing an empty or absent peer certificate was incorrectly applied beyond the initial handshake phase, specifically while a post-handshake CertificateRequest was outstanding. The fix scopes this exemption strictly to the initial handshake, requiring a valid peer certificate and CertificateVerify during post-handshake authentication, consistent with the configured verification mode (FAIL_IF_NO_PEER_CERT). Clients and servers not using post-handshake authentication are unaffected.
Potential Impact
Affected TLS 1.3 servers may accept a client's Finished message without proper client certificate authentication during post-handshake authentication, potentially allowing unauthorized clients to complete the handshake phase without presenting valid credentials. This undermines the intended client authentication mechanism post-handshake. However, this only affects wolfSSL TLS 1.3 servers configured with post-handshake authentication support and client certificate verification after handshake. Clients and servers not using these features are not impacted.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid enabling post-handshake authentication with client certificate requests on wolfSSL TLS 1.3 servers. Monitor vendor communications for updates and apply official patches or configuration changes once provided.
GHSA-gq94-hf88-g4wv
Description
A vulnerability in TLS 1.3 post-handshake authentication (PHA) in wolfSSL allows a server to accept a client's Finished message without the client sending a Certificate and CertificateVerify when post-handshake authentication is enabled. This occurs because the exemption for an empty or absent peer certificate, intended only for the initial handshake, was incorrectly applied during post-handshake CertificateRequest. Only TLS 1.3 servers built with post-handshake authentication support and configured to request client certificates after the handshake are affected. Clients and servers not using post-handshake authentication are not impacted.
CVSS v4.0
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-55962) affects TLS 1.3 servers using wolfSSL with post-handshake authentication enabled (WOLFSSL_POST_HANDSHAKE_AUTH / --enable-postauth) and configured to verify client certificates post-handshake (WOLFSSL_VERIFY_POST_HANDSHAKE). The issue is that the server could accept a client's Finished message without the client having sent the required Certificate and CertificateVerify messages during post-handshake authentication. This happens because the exemption allowing an empty or absent peer certificate was incorrectly applied beyond the initial handshake phase, specifically while a post-handshake CertificateRequest was outstanding. The fix scopes this exemption strictly to the initial handshake, requiring a valid peer certificate and CertificateVerify during post-handshake authentication, consistent with the configured verification mode (FAIL_IF_NO_PEER_CERT). Clients and servers not using post-handshake authentication are unaffected.
Potential Impact
Affected TLS 1.3 servers may accept a client's Finished message without proper client certificate authentication during post-handshake authentication, potentially allowing unauthorized clients to complete the handshake phase without presenting valid credentials. This undermines the intended client authentication mechanism post-handshake. However, this only affects wolfSSL TLS 1.3 servers configured with post-handshake authentication support and client certificate verification after handshake. Clients and servers not using these features are not impacted.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid enabling post-handshake authentication with client certificate requests on wolfSSL TLS 1.3 servers. Monitor vendor communications for updates and apply official patches or configuration changes once provided.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-gq94-hf88-g4wv
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-55962"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a3ef7d127e9c79719002b2c
Added to database: 06/26/2026, 22:06:09 UTC
Last enriched: 06/26/2026, 22:37:48 UTC
Last updated: 06/27/2026, 00:31:22 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.