{"id":"CVE-2026-89134","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-89134","summary":"Subject CN name-constraint check bypassed when non-DNS SAN present","details":"A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN dNSName name-constraint check. The CN-as-DNS fallback was gated on cert->subjectCN != NULL && cert->altNames == NULL && !cert->isCA instead of \"no dNSName SAN\", so an out-of-scope CN was accepted. This incomplete fix from CVE-2026-6731, leading to the name-constraint check issue, was introduced in wolfSSL version 5.9.2.","published":"2026-09-27T09:16:58.067Z","modified":"2026-10-01T03:30:54.776000380Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/wolfSSL/wolfssl/pull/10837","label":"wolfSSL/wolfssl#10837"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89134.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89134"},{"type":"FIX","url":"https://github.com/wolfSSL/wolfssl/pull/10837"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-10-01T03:30:54.776000380Z"}}