VYPR
patchPublished Sep 29, 2026· 1 source

wolfSSL 5.9.4 Addresses 11 TLS Vulnerabilities, Enhances Post-Quantum Cryptography

wolfSSL's latest update, version 5.9.4, resolves eleven security flaws in its embedded TLS/cryptography library, including three high-severity issues, and significantly boosts post-quantum cryptography support.

wolfSSL has issued version 5.9.4 of its embedded Transport Layer Security (TLS) and cryptography library, patching a total of eleven security vulnerabilities. The update is crucial for the myriad of IoT devices, embedded systems, servers, and applications that rely on wolfSSL for secure communication via TLS and Datagram TLS (DTLS). The release addresses three high-severity, four medium-severity, and four low-severity Common Vulnerabilities and Exposures (CVEs), though the company notes that many of these flaws are contingent on specific build configurations, APIs, or non-default settings.

Organizations utilizing wolfSSL are advised to review their compilation flags and update affected installations. Particular attention should be paid to deployments that employ OpenSSL-compatible settings, Raw Public Keys (RPK), Online Certificate Status Protocol (OCSP) stapling, certificate revocation checks, or TLS 1.2 session resumption. The three high-severity vulnerabilities identified could potentially weaken TLS peer authentication in certain build scenarios, opening the door for certificate forgery.

Among the critical flaws, CVE-2026-93302 affects deployments using the WOLFSSL_TRUST_PEER_CERT option, potentially allowing a forged certificate authority (CA) clone to pass validation if an attacker possesses the target's trusted CA certificates. This could impact compatibility-focused configurations used with popular software like nginx, HAProxy, and Apache HTTP Server. Another high-severity issue, CVE-2026-89102, impacts clients that enable RFC 6961 multiple OCSP response stapling. A vulnerable client might accept a certificate within a server-provided chain as a valid CA without verifying its authority, enabling an attacker to forge certificates for arbitrary identities.

The third high-severity vulnerability, CVE-2026-89136, targets clients compiled with Raw Public Key support, which is typically disabled by default but can be enabled via specific build options. A malicious server could exploit this to send an unsolicited RPK and bypass standard X.509 certificate-chain validation. Additionally, the update rectifies certificate name-constraint validation errors, including a medium-severity flaw where a certificate could bypass DNS name constraints if an unconstrained intermediate CA was positioned between the constrained intermediate CA and the leaf certificate.

Further fixes in wolfSSL 5.9.4 address an out-of-order ChangeCipherSpec message in TLS 1.2 and DTLS 1.2, an OCSP and CRL fallback issue that could lead to the acceptance of revoked certificates, and a session-cache reference problem affecting legacy TLS 1.2 and DTLS 1.2 resumption flows. A potential use-after-free condition during TLS shutdown has also been resolved. Administrators are cautioned that simply updating the shared library might not be sufficient for long-running applications; restarting the affected process or WOLFSSL_CTX may be necessary to clear potentially persisted state in memory.

Beyond the security patches, wolfSSL 5.9.4 introduces substantial enhancements to its post-quantum cryptography (PQC) capabilities. The library now offers native Falcon signature support, removing the previous dependency on the liboqs library. It also incorporates FrodoKEM, a post-quantum key encapsulation mechanism, with optimized implementations for various architectures including x86_64 and ARM. The update adds SLH-DSA authentication for TLS 1.3 and DTLS 1.3 handshakes across all twelve parameter sets.

Developers can now configure post-quantum-only TLS 1.3 environments using ML-KEM key exchange with ML-DSA or SLH-DSA authentication, completely omitting traditional cryptographic algorithms like RSA, ECC, or Diffie-Hellman. wolfSSL has also integrated AVX512 acceleration for ML-KEM and ML-DSA, added ML-DSA support for PKCS#7 and CMS SignedData, and introduced an --enable-all-quantum-crypto configuration bundle. These advancements position wolfSSL as a forward-looking solution for organizations preparing their infrastructure against the future threat of cryptographically relevant quantum computers.

Organizations running older versions of wolfSSL, particularly 5.9.2 or earlier, are strongly encouraged to upgrade to version 5.9.4. Priority should be given to systems that utilize trusted-peer certificate APIs, multi-OCSP stapling, Raw Public Keys, OpenSSL compatibility APIs, OCSP and CRL checking, and legacy session resumption features, as these are the areas most impacted by the newly disclosed vulnerabilities.

Synthesized by Vypr AI