CVE-2025-7395
A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.
- CVSS 4.0
- 9.2 CRITICAL
- EPSS
- 0.2% (13th percentile)
- Weakness
- CWE-295
- NVD status
- Deferred
- Published
- 2025-07-18
- Attack patterns
- CAPEC-94
Fix
Upgrade to wolfSSL commit fbc483e23a3e42d5430a838230db1f8c90b88d41 or newer
Workaround
Manually load CA certificates into wolfSSL instead of relying on apple native certificate verification, or upgrade to wolfSSL commit fbc483e23a3e42d5430a838230db1f8c90b88d41 or newer
No indexed exploits for CVE-2025-7395 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-7395 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.