Skip to main content
EPSS 0.2%top 94%

In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to… (CVE-2026-89102)

0
Medium
Published: 09/27/2026 (09/27/2026, 10:16:00 UTC)
Source: GCVE Database
Product: wolfssl

Description

wolfSSL versions 5.7.2 through 5.9.2 contain a client-side flaw in the implementation of RFC 6961 multiple OCSP response stapling. This flaw allows a client that enables OCSP stapling with the HAVE_CERTIFICATE_STATUS_REQUEST_V2 feature and uses wolfSSL_UseOCSPStaplingV2 with WOLFSSL_CSR2_OCSP_MULTI to accept any certificate in the peer's chain as a certificate authority without proper authorization verification. An attacker with a certificate chaining to a trusted CA and its private key can forge certificates for arbitrary identities accepted as valid by the client. The forged certificate is stored in the persistent trust store, affecting subsequent connections even without OCSP multi usage.

CVSS v3.1

Score 6.5medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected software

Ubuntu:16.04:LTSmore threats →ghsa
wolfssl
pkg:deb/ubuntu/wolfssl?arch=source&distro=xenial
Affected versions
=3.4.8+dfsg-1
Ubuntu:18.04:LTSmore threats →ghsa
wolfssl
pkg:deb/ubuntu/wolfssl?arch=source&distro=bionic
Affected versions
=3.10.2+dfsg-2=3.12.0+dfsg-1=3.12.2+dfsg-1=3.13.0+dfsg-1
Ubuntu:20.04:LTSmore threats →ghsa
wolfssl
pkg:deb/ubuntu/wolfssl?arch=source&distro=focal
Affected versions
=4.1.0+dfsg-2=4.2.0+dfsg-1=4.2.0+dfsg-2=4.2.0+dfsg-3=4.3.0+dfsg-2
Ubuntu:22.04:LTSmore threats →ghsa
wolfssl
pkg:deb/ubuntu/wolfssl?arch=source&distro=jammy
Affected versions
=4.6.0-3=5.0.0-1=5.1.1-1=5.2.0-1=5.2.0-2
Ubuntu:24.04:LTSmore threats →ghsa
wolfssl
pkg:deb/ubuntu/wolfssl?arch=source&distro=noble
Affected versions
=5.5.4-2=5.5.4-2.1=5.6.4-2=5.6.6-1.2=5.6.6-1.3=5.6.6-1.3build1
Ubuntu:26.04:LTSmore threats →ghsa
wolfssl
pkg:deb/ubuntu/wolfssl?arch=source&distro=resolute
Affected versions
=5.7.2-0.1=5.8.2-1.2=5.8.4-1=5.9.1-0.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/02/2026, 18:05:01 UTC

Technical Analysis

The vulnerability in wolfSSL versions 5.7.2 through 5.9.2 arises from improper client-side validation of certificates when multiple OCSP response stapling is enabled via the HAVE_CERTIFICATE_STATUS_REQUEST_V2 feature and wolfSSL_UseOCSPStaplingV2 API. The client incorrectly accepts any certificate in the peer's chain as a valid CA without verifying its authorization to act as one. This allows an attacker possessing any certificate chaining to a trusted CA, along with its private key, to forge certificates for arbitrary identities that the client will accept as valid. Additionally, the forged end entity certificate is stored persistently, impacting future connections that reuse the SSL context, even if OCSP multi usage is not enabled. This flaw was identified through internal wolfSSL testing.

Potential Impact

An attacker who has a certificate and private key chaining to a CA trusted by the client can forge arbitrary certificates accepted as valid by the vulnerable wolfSSL client. This undermines the trust model of certificate validation, potentially allowing impersonation of arbitrary identities. The persistent storage of the forged certificate in the trust store means the impact extends beyond a single connection, affecting subsequent connections that reuse the SSL context. The CVSS v3.1 score is 6.5 (medium severity), reflecting the network attack vector, low attack complexity, required privileges, no user interaction, and impact on integrity but not confidentiality or availability.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid enabling OCSP stapling with the HAVE_CERTIFICATE_STATUS_REQUEST_V2 feature and wolfSSL_UseOCSPStaplingV2 with WOLFSSL_CSR2_OCSP_MULTI. Monitor wolfSSL vendor communications for patches addressing this vulnerability and apply them promptly once released.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
UBUNTU-CVE-2026-89102
Osv Schema Version
1.7.0
Ecosystems
["Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
Cvss Version
3.1

Threat ID: 6abfeea2a43b0b3b89e554ba

Added to database: 10/02/2026, 17:49:22 UTC

Last enriched: 10/02/2026, 18:05:01 UTC

Last updated: 10/03/2026, 02:46:07 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses