6.3
MEDIUM CVSS 4.0
CVE-2026-55964
Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption)
Description

Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have the keyCertSign key usage when a Key Usage extension is present, but chain-supplied temporary CAs (WOLFSSL_TEMP_CA) added while building a certificate path were previously exempted from this check, so an intermediate asserting CA:TRUE but lacking keyCertSign was accepted as a signing CA. The check now applies to chain-supplied temporary CAs as well; only operator-loaded root certificates (WOLFSSL_USER_CA) and self-signed roots remain exempt. Per RFC 5280 an absent Key Usage extension implies all usages, so the requirement is enforced only when the extension is actually present (extKeyUsageSet). Affects the OpenSSL-compatibility certificate-path-building path (X509_verify_cert / X509_STORE, OPENSSL_EXTRA/OPENSSL_ALL), where untrusted chain intermediates are added as temporary CAs; native (non-OpenSSL-compat) certificate verification does not create temporary CAs and is unaffected. Within those builds, the check applies unless ALLOW_INVALID_CERTSIGN is defined.

INFO

Published Date :

June 25, 2026, 7:30 p.m.

Last Modified :

June 25, 2026, 7:30 p.m.

Remotely Exploit :

Yes !

Source :

wolfSSL
Affected Products

The following products are affected by CVE-2026-55964 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 4.0 MEDIUM 50d2cd11-d01a-48ed-9441-5bfce9d63b27
CVSS 4.0 MEDIUM [email protected]
Solution
Update WOLFSSL to enforce keyCertSign for intermediate CAs, preventing invalid certificate chains.
  • Update WOLFSSL library to the latest version.
  • Ensure intermediate CA certificates have keyCertSign usage.
  • Avoid using temporary CAs unless necessary.
  • Define ALLOW_INVALID_CERTSIGN if needed.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-55964 vulnerability anywhere in the article.

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.