CVE-2025-22874

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

  • Published Jun 11, 2025
  • CVSS 7.5 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2025-22874 at the National Vulnerability Database