A certificate verification error in wolfSSL when building...
Critical severity
Unreviewed
Published
Jul 19, 2025
to the GitHub Advisory Database
•
Updated Jul 19, 2025
Description
Published by the National Vulnerability Database
Jul 18, 2025
Published to the GitHub Advisory Database
Jul 19, 2025
Last updated
Jul 19, 2025
A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL
client failing to properly verify the server certificate's domain name,
allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.
References