Go standard library crypto/x509
12 known vulnerabilities in Go standard library crypto/x509, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-27145 CVSS 6.5 medium (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This…
- CVE-2026-33810 CVSS 8.2 high When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs…
- CVE-2026-32281 CVSS 7.5 high Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of…
- CVE-2026-32280 CVSS 7.5 high During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are…
- CVE-2026-27138 CVSS 5.9 medium Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the chain has excluded…
- CVE-2026-27137 CVSS 7.5 high When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local…
- CVE-2025-61727 CVSS 6.5 medium An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example…
- CVE-2025-61729 CVSS 7.5 high Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out…
- CVE-2025-58188 CVSS 7.5 high Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they…
- CVE-2025-58187 CVSS 7.5 high Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the…
- CVE-2025-22874 CVSS 7.5 high Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected…
- CVE-2024-45341 CVSS 6.1 medium A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the…