Vulnerability GO-2026-4866

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
6 months ago
April 07, 2026 at 10:53 PM UTC
Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
>=1.26.0-0 <1.26.2
>=1.26.0-0 <1.26.2

Summary

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

Details

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint.

This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

Impacted packages

Timeline

Published
6 months ago
April 07, 2026 at 10:53 PM UTC
Last Modified
2 hours ago
October 07, 2026 at 10:41 AM UTC