Back to search
CVE-2025-7395
Published: Jul 18, 2025
Modified: Jul 21, 2025
PUBLISHED
Description
A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.
| Vendor | Product | Versions |
|---|---|---|
wolfSSL | wolfSSL | affected 5.6.4 - <= 5.8.0 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now