CVE-2026-7532
Received Received - Intake
wolfSSL IP Address Name Constraints Bypass

Publication date: 2026-06-25

Last updated on: 2026-06-25

Assigner: wolfSSL Inc.

Description
iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowing a certificate to bypass an issuing CA's IP address constraints.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-25
Last Modified
2026-06-25
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability involves a bypass of IP address name constraints in the WOLFSSL library when the configuration option WOLFSSL_IP_ALT_NAME is not defined.

Specifically, IP address name constraints are not enforced in this configuration, which allows a certificate to bypass the issuing Certificate Authority's (CA) IP address constraints.

Impact Analysis

Because IP address name constraints are not enforced, an attacker could use a certificate that bypasses the intended IP address restrictions set by the issuing CA.

This could lead to unauthorized use of certificates for IP addresses that should have been restricted, potentially enabling man-in-the-middle attacks or unauthorized access to network resources.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-7532. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart