CVE-2025-7395

Severity CVSS v4.0:
CRITICAL
Type:
CWE-295 Improper Certificate Validation
Publication date:
18/07/2025
Last modified:
22/07/2025

Description

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL<br /> client failing to properly verify the server certificate&amp;#39;s domain name,<br /> allowing any certificate issued by a trusted CA to be accepted regardless of the hostname.

References to Advisories, Solutions, and Tools