CVE-2026-89136

Summary

When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited server_cert_type=RawPublicKey which allowed a malicious or misbehaving server to bypass authentication. RPK is off by default and only enabled in –enable-rpk OR –enable-all OR –enable-distro AKA HAVE_RPK builds.

Affected Software

VendorProductVersion RangeStatus
wolfSSLwolfSSL5.6.0 <= 5.9.2affected

Weaknesses

  • CWE-287: CWE-287 Improper Authentication

References