VYPR
High severity7.5NVD Advisory· Published Jun 25, 2026· Updated Jul 1, 2026

CVE-2026-7532

CVE-2026-7532

Description

iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowing a certificate to bypass an issuing CA's IP address constraints.

Affected products

3
  • WolfSSL/Wolfsslllm-fuzzy3 versions
    (expand)+ 2 more
    • (no CPE)
    • cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*range: <5.9.2
    • (no CPE)

Patches

Vulnerability mechanics

References

3

News mentions

1