Sploitus

CVE-2025-7395

No indexed exploits for CVE-2025-7395 yet

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.

Affected products
Debian, Wolfssl
CVSS 4.0
9.2 CRITICAL
EPSS
0.2% (13th percentile)
Weakness
CWE-295
NVD status
Deferred
Published
2025-07-18
Attack patterns
CAPEC-94

Fix

Upgrade to wolfSSL commit fbc483e23a3e42d5430a838230db1f8c90b88d41 or newer

Workaround

Manually load CA certificates into wolfSSL instead of relying on apple native certificate verification, or upgrade to wolfSSL commit fbc483e23a3e42d5430a838230db1f8c90b88d41 or newer

CVE-2025-7395 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-7395 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-7395 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.