CRITICAL🇵🇱 Wersja polska

CVE-2026-42508

CVSS 9.1pub. 2026-05-22upd. 2026-09-01

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

🤖 AI Analysis
How it works

During certificate or signature verification, the library only checked the direct key (key), omitting verification of the revocation status of the associated CA signature key (key.SignatureKey). An attacker with access to a revoked CA SignatureKey could generate signatures or certificates that were incorrectly recognized as valid. After the fix, both fields — key and key.SignatureKey — are verified for presence on the revocation list.

Impact

An attacker can bypass certificate or CA key revocation verification mechanisms, leading to unauthorized access to protected resources or violation of digital signature integrity.

Mitigation & patch

Apply patches available from the vendor according to references (https://go.dev/cl/781220, https://go.dev/issue/79568, https://pkg.go.dev/vuln/GO-2026-5021).

Who is affected

Applications using the Golang Crypto library — versions indicated in vendor references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Golang Crypto

    APP
    Golang
    < 0.52.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-39832CRITICAL9.1PL ✓same product

Golang Crypto: pominięcie ograniczeń przy przekazywaniu kluczy do zdalnego agenta SSH

CVE-2026-39833CRITICAL9.1PL ✓same product

Golang Crypto: brak wymuszenia ograniczenia ConfirmBeforeUse w NewKeyring()

CVE-2026-39831CRITICAL9.1PL ✓same product

Brak weryfikacji flagi User Presence w FIDO/U2F w Golang Crypto

CVE-2026-39830CRITICAL9.1PL ✓same product

Golang Crypto: resource leak przez niezamawiane odpowiedzi SSH global request

CVE-2026-39834CRITICAL9.1PL ✓same product

Integer overflow w Golang Crypto SSH — nieskończona pętla przy zapisie >4GB