Threats Tagged 'ghsa-m732-8qwx-39wm'
View all threats tagged with 'ghsa-m732-8qwx-39wm'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-m732-8qwx-39wm'
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability in wolfSSL versions 5.8.4 through 5.9.2 with specific build configurations allows a failed X509_verify_cert call to permanently add an unverified attacker CA to the shared CertManager. This bypasses certificate validation for all consumers relying on the shared CertManager, including native TLS, OCSP, CRL, and direct certificate manager verification. The issue occurs only when the macros OPENSSL_EXTRA, NO_CERTS, and WOLFCRYPT_ONLY are set in a particular way or when built with --enable-opensslextra, and the application explicitly calls X509_verify_cert. Join the discussion | GCVE Database | 09/27/2026, 12:30:20 UTC Added: 10/03/2026, 17:22:06 UTC |
Showing 1 to 1 of 1 result