Security Advisory

CVE-2025-7395

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-18 22:15:59
Last updated 2025-07-21 14:56:52
Assigner wolfSSL
CVSS score not scored
State PUBLISHED

Description

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.