Research / Finding
URI nameConstraints not enforced in ConfirmNameConstraints() F-WOLFSSL-NC-URI-001
Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.
Read the evidence · View in research browse
Recorded evidence
7.0high
URI nameConstraints not enforced in ConfirmNameConstraints()
Fixed in: wolfSSL 5.9.1
patched
details
Finding IDs F-WOLFSSL-NC-URI-001 CVE CVE-2026-5263 GHSA GHSA-9xmr-c663-3rpr Status patched Fixed in wolfSSL 5.9.1 Recorded credit finder: Oleh Konko @1seal (wolfSSL CNA / v5.9.1-stable release note) Note GHSA-9xmr-c663-3rpr · fixed in PR 10048 CVSS vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N CVE registry state PUBLISHED CVE state checked 23 Sep 2026 F-WOLFSSL-NC-URI-001: Verification failures. URI name-constraint parsing fails to enforce the intended certificate boundary. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-WOLFSSL-NC-URI-001
Security area (1seal assessment): Identity. URI name-constraint parsing fails to enforce the intended certificate boundary. Reviewed 24 Sep 2026.
Clarify or correct this record privately . The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy .
How this page groups evidence This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules .