CVE Database
/

CVE-2025-7395

Back to search

CVE-2025-7395

Published: Jul 18, 2025

Modified: Jul 21, 2025

PUBLISHED

Description

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.

VendorProductVersions

wolfSSL

wolfSSL

affected
5.6.4 - <= 5.8.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now