NVD HIGH: CVE-2026-94418 — Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate sig...
Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to keep peak memory down, then merges the two results, but it merged the signature result back only when the parse returned 0, so any parse error hid it. ParseCertRelative() reaches its validity-date, name-constraint and critical-extension checks only after ConfirmSignature() has
CVE-2026-94418