CVE Vulnerabilities

CVE-2025-7395

Improper Certificate Validation

Published: Jul 18, 2025 | Modified: Jul 18, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificates domain name, allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Potential Mitigations

References