CVE-2025-22874 affecting package msft-golang for versions less than 1.24.1-3
Details
Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.