VYPR
Medium severity5.3NVD Advisory· Published Jun 25, 2026· Updated Jun 26, 2026

CVE-2026-10592

CVE-2026-10592

Description

Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildcard DNS SAN that should be rejected by the issuing CA's permitted/excluded DNS name constraints could be accepted.

Affected products

3
  • WolfSSL/Wolfssl2 versions
    cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*range: >=3.9.10,<5.9.2
    • (no CPE)
  • Debian/wolfsslllm-create

Patches

Vulnerability mechanics

References

2

News mentions

1