{"id":"CVE-2026-89136","published":"2026-09-27T10:16:59.287","lastModified":"2026-09-29T17:17:12.787","description":"When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited server_cert_type=RawPublicKey which allowed a malicious or misbehaving server to bypass authentication. RPK is off by default and only enabled in --enable-rpk OR --enable-all OR --enable-distro AKA HAVE_RPK builds.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-287"],"vendors":[],"products":[],"references":[{"url":"https://github.com/wolfSSL/wolfssl/pull/11009","tags":[]}],"exploitRefs":[{"url":"https://github.com/wolfSSL/wolfssl/pull/11009","tags":[]}],"hasPoc":true,"ai":null}