When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:NGolang Go
APPGolang1.26.0 – 1.26.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
References
Related vulnerabilities
CVE-2026-27143CRITICAL9.8PL ✓same product
Błąd arytmetyczny w kompilatorze Golang Go prowadzący do uszkodzenia pamięci
CVE-2025-66630CRITICAL9.2PL ✓same product
Przewidywalne UUID w Fiber v2 — podatność na generowanie słabych identyfikatorów
CVE-2025-68121CRITICAL10.0PL ✓same product
Golang crypto/tls: błędna walidacja certyfikatów przy wznawianiu sesji TLS
CVE-2024-24790CRITICAL9.8PL ✓same product
Błędna klasyfikacja adresów IPv4-mapped IPv6 w bibliotece standardowej Go
CVE-2023-39320CRITICAL9.8PL ✓same product
Nieautoryzowane wykonanie kodu przez dyrektywę toolchain w Go 1.21