CVE-2026-27137

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.
Configurations

Configuration 1 (hide)

cpe:2.3:a:golang:go:1.26.0:*:*:*:*:*:*:*

History

21 Apr 2026, 14:40

Type Values Removed Values Added
CPE cpe:2.3:a:golang:go:1.26.0:*:*:*:*:*:*:*
First Time Golang go
Golang
References () https://go.dev/cl/752182 - () https://go.dev/cl/752182 - Mailing List
References () https://go.dev/issue/77952 - () https://go.dev/issue/77952 - Issue Tracking
References () https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk - () https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk - Release Notes
References () https://pkg.go.dev/vuln/GO-2026-4599 - () https://pkg.go.dev/vuln/GO-2026-4599 - Vendor Advisory
CWE CWE-295

10 Mar 2026, 18:18

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) Al verificar una cadena de certificados que contiene un certificado con múltiples restricciones de dirección de correo electrónico que comparten porciones locales comunes pero porciones de dominio diferentes, estas restricciones no se aplicarán correctamente, y solo la última restricción será considerada.

06 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-06 22:16

Updated : 2026-04-21 14:40


NVD link : CVE-2026-27137

Mitre link : CVE-2026-27137

CVE.ORG link : CVE-2026-27137


JSON object : View

Products Affected

golang

  • go
CWE
CWE-295

Improper Certificate Validation