CVE-2026-6412
Received Received - Intake
SHA-1/MD5 Certificate Processing Non-Compliance with RFC 8446

Publication date: 2026-06-25

Last updated on: 2026-06-25

Assigner: wolfSSL Inc.

Description
Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate processing.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-25
Last Modified
2026-06-25
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-327 The product uses a broken or risky cryptographic algorithm or protocol.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability concerns certificate policy and compliance with RFC 8446, specifically regarding the continued acceptance of SHA-1 and MD5 hashing algorithms in certificate processing.

SHA-1 and MD5 are cryptographic hash functions that have known weaknesses, and their continued acceptance in certificate validation processes raises security and compliance concerns.

Impact Analysis

The impact of this vulnerability is relatively low, as indicated by the CVSS base score of 2.3.

However, accepting certificates that use SHA-1 or MD5 can expose systems to risks such as weakened cryptographic assurance, potential certificate forgery, or man-in-the-middle attacks due to the vulnerabilities in these hash algorithms.

Compliance Impact

This vulnerability involves certificate policy and RFC 8446 compliance concerns due to the continued acceptance of SHA-1/MD5 in certificate processing.

Since SHA-1 and MD5 are considered weak cryptographic hash functions, their continued acceptance in certificate processing could undermine the security assurances required by standards and regulations such as GDPR and HIPAA, which mandate strong cryptographic protections to safeguard sensitive data.

Therefore, this vulnerability may negatively impact compliance with these regulations by allowing weaker cryptographic methods that could lead to potential data integrity and confidentiality issues.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6412. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart