JLSEC-2026-758 Medium 5.7
iPAddress name constraints bypass when `WOLFSSL_IP_ALT_NAME` is not defined
iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowing a certificate to bypass an issuing CA's IP address constraints.
References
- https://github.com/advisories/GHSA-h4jr-6mf9-63fq
- https://github.com/wolfSSL/wolfssl/pull/10354
- https://nvd.nist.gov/vuln/detail/CVE-2026-7532
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2026-2409
- https://www.wolfssl.com/docs/security-vulnerabilities
- https://www.wolfssl.com/docs/security-vulnerabilities/