CVE-2025-15346
Severity CVSS v4.0:
CRITICAL
Type:
CWE-287
Authentication Issues
Publication date:
08/01/2026
Last modified:
08/01/2026
Description
A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client certificate requirements to not be fully enforced. <br />
<br />
Because the WOLFSSL_VERIFY_FAIL_IF_NO_PEER_CERT flag was not included, the behavior effectively matched CERT_OPTIONAL: a peer certificate was verified if presented, but connections were incorrectly authenticated when no client certificate was provided. <br />
<br />
This results in improper authentication, allowing attackers to bypass mutual TLS (mTLS) client authentication by omitting a client certificate during the TLS handshake. <br />
<br />
The issue affects versions up to and including 5.8.2.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL



