wolfSSL CNA finder credit: Oleh Konko (@1seal). Fix PR #10239 opened by @gasbytes; code authorship is not claimed.
Disclosure date
Note
The published CNA record references the same PR #10239 already recorded under F-WOLFSSL-CRL-001. F-WOLFSSL-CRL-SCOPE-COLLAPSE-001 is an alternate ID for that result, not a second independent defect. wolfSSL 5.9.2 release notes confirm the fix and reporter credit: https://github.com/wolfSSL/wolfssl/blob/v5.9.2-stable/ChangeLog.md. The LOW 1.0 assessment is the wolfSSL CNA assessment, separate from any original report assessment.
F-WOLFSSL-CRL-001: Verification failures. Unknown critical CRL extensions are not rejected as required. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
F-WOLFSSL-CRL-SCOPE-COLLAPSE-001: Verification failures. Unknown critical CRL extensions are not rejected as required. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
wolfSSL CNA finder credit: Oleh Konko (@1seal). Fix PR #10239 opened by @gasbytes; code authorship is not claimed.
Reported date
Note
CVE-2026-6450 covers this existing CRL fix. The two Finding IDs identify the same result; CNA finder credit and PR authorship are separate. Published CNA CVSS 4.0: 1.0 LOW; no revision of the original report assessment.
Rationale
rejects CRLs with unrecognized critical extensions per RFC 5280 section 5.2 instead of silently accepting a revocation scope-bypass condition. public PR #10239 merged on 2026-04-21.
PR opened by
@gasbytes
PR state observed
closed; GitHub merged: true; 2026-09-24
PR observation basis
Public PR metadata recorded in the 2026-09-24 evidence audit; not a live status feed.
Contribution boundary
Report-associated upstream work; @1seal code authorship is not claimed. Credit, where recorded, is a separate fact.
F-WOLFSSL-CRL-001: Verification failures. Unknown critical CRL extensions are not rejected as required. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
F-WOLFSSL-CRL-SCOPE-COLLAPSE-001: Verification failures. Unknown critical CRL extensions are not rejected as required. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.