
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-89136 is an authentication bypass vulnerability in wolfSSL affecting the Raw Public Key (RPK) implementation in TLS 1.2, TLS 1.3, and DTLS 1.2 connections. When RPK is enabled, the client side of a connection could accept an unsolicited server_cert_type=RawPublicKey extension from the server, allowing a malicious or misbehaving server to bypass authentication. Affected versions span wolfSSL 5.6.0 through 5.9.2 (inclusive). The vulnerability was disclosed on September 27, 2026, with a patch merged on August 11, 2026. It carries a CVSS v4.0 base score of 8.3 (High) (GitHub Advisory, wolfSSL PR #11009).
The root cause is classified as CWE-287 (Improper Authentication): wolfSSL's client-side TLS handshake processing failed to enforce "offered vs. received" constraints for the server_cert_type extension defined in RFC 7250 and RFC 8446. Specifically, the client did not verify that it had previously advertised support for RawPublicKey before accepting a server_cert_type=RawPublicKey response from the server, allowing an unsolicited negotiation to succeed. The fix, contributed by Christos Papakonstantinou of Cantina Security and implemented in src/tls.c, enforces that only cert-type values explicitly offered by the client during the handshake are accepted. This vulnerability is only present in builds compiled with --enable-rpk, --enable-all, or --enable-distro flags (i.e., HAVE_RPK builds); RPK is off by default (wolfSSL PR #11009, GitHub Advisory).
Successful exploitation enables a malicious or adversary-in-the-middle server to bypass server authentication in TLS/DTLS sessions, meaning the client cannot verify the server's true identity. This primarily impacts integrity (CVSS v4 Vulnerable System Integrity: High) and to a lesser extent confidentiality (Low), as an attacker who impersonates a legitimate server could intercept or manipulate data exchanged during the session. Availability is not directly impacted. The attack scope is limited to systems using wolfSSL compiled with RPK support, but within that scope, any TLS 1.2, TLS 1.3, or DTLS 1.2 client connection is at risk of man-in-the-middle interception (GitHub Advisory, wolfSSL PR #11009).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.0055 (0.55%), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to be in a network position to intercept or control TLS handshake traffic (Attack Requirements: Present), limiting opportunistic exploitation, though no privileges or user interaction are required once that position is achieved.
--enable-rpk, --enable-all, or --enable-distro (i.e., HAVE_RPK defined), running versions 5.6.0 through 5.9.2.client_cert_type extension advertising RPK support.server_cert_type=RawPublicKey even if the client did not request it. Due to the vulnerability, the unpatched wolfSSL client accepts this unsolicited extension.server_cert_type=RawPublicKey extension in TLS ServerHello messages on connections where the client did not advertise RPK support in its ClientHello; TLS handshakes completing with a raw public key credential rather than an X.509 certificate chain.cert_type=RawPublicKey on clients not configured to use RPK; anomalous certificate type negotiation entries in application-level TLS debug logs.Upgrade wolfSSL to a version beyond 5.9.2 that includes the fix merged in pull request #11009 (merged August 11, 2026). If RPK functionality is not required, recompile wolfSSL without the --enable-rpk, --enable-all, or --enable-distro build flags to eliminate the HAVE_RPK code path entirely and remove the attack surface. Organizations unable to upgrade immediately should audit their build configurations to confirm RPK is not inadvertently enabled via --enable-all or --enable-distro (wolfSSL PR #11009, GitHub Advisory).
The vulnerability was reported by Christos Papakonstantinou of Cantina Security, who also reported several other issues addressed in the same pull request (wolfSSL PR #11009). No significant broader media coverage or notable public researcher commentary beyond the GitHub advisory and pull request discussion has been identified at this time.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."