wolfSSL 5.9.4 (25 Sep / advisories ~28–29 Sep): 11 TLS/X.509 fixes — High OCSP stapling & RPK auth issues
wolfSSL release 5.9.4 (25 September 2026; security-vulnerabilities page listing the fixed CVEs amplified ~28–29 Sep including Cyber Security News 29 Sep) ships eleven security fixes. Highest-profile High issues include CVE-2026-89102 (client RFC 6961 multiple-OCSP stapling path can enable certificate forgery when HAVE_CERTIFICATE_STATUS_REQUEST_V2 / wolfSSL_UseOCSPStaplingV2 is used; 5.7.2–5.9.2), CVE-2026-89136 (TLS/DTLS client accepts unsolicited server_cert_type=RawPublicKey and may bypass authentication — RPK off by default; needs --enable-rpk / --enable-all / --enable-distro; 5.6.0–5.9.2), CVE-2026-93302 (MatchTrustedPeer / WOLFSSL_TRUST_PEER_CERT forged CA clones), and CVE-2026-11310 (OpenSSL-compat X.509 trust-chain bypass under --enable-opensslextra). Also Medium name-constraint / CertManager issues (CVE-2026-89133/89134/89135, CVE-2026-93304) and Low DoS/UAF/revocation/session-cache items (CVE-2026-15442, 94417–94419). No Critical in this 5.9.4 set on the vendor page. No in-the-wild exploitation stated. Primary: wolfSSL security vulnerabilities page; release: GitHub wolfSSL 5.9.4.
- Product
- wolfSSL (embedded TLS / X.509 library)
- Versions
- Fixed: wolfSSL 5.9.4 (25 Sep 2026). Affected ranges vary by CVE (examples: 5.7.2–5.9.2 for CVE-2026-89102; 5.6.0–5.9.2 for CVE-2026-89136; see vendor page for each issue and build flags such as HAVE_RPK / OPENSSL_EXTRA / WOLFSSL_TRUST_PEER_CERT).
- Exploited in Australia?
- unknown
- Patch to
- Upgrade embedded/products using wolfSSL to 5.9.4+. Audit build flags (OCSP multi-stapling, RPK, OPENSSL_EXTRA, TRUST_PEER_CERT, SMALL_CERT_VERIFY) even after upgrade if custom configs remain on older trains; re-test certificate validation and revocation paths.
Primary: wolfSSL — Security Vulnerabilities (fixes in 5.9.4) · Vendor: wolfSSL — Release 5.9.4 (25 Sep 2026) · CVE: CVE-2026-89102, CVE-2026-89136, CVE-2026-93302, CVE-2026-11310, CVE-2026-89133, CVE-2026-93304, CVE-2026-15442 · Cyber Security News — wolfSSL 5.9.4 eleven TLS fixes (29 Sep 2026)
