Vulnerability GO-2026-4946

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
5 months ago
April 07, 2026 at 10:53 PM UTC
Inefficient policy validation in crypto/x509
<1.25.9
<1.25.9

Summary

Inefficient policy validation in crypto/x509

Details

Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service.

This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

Impacted packages

Timeline

Published
5 months ago
April 07, 2026 at 10:53 PM UTC
Last Modified
2 hours ago
September 28, 2026 at 10:56 AM UTC