BIT-golang-2026-27137

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/golang/BIT-golang-2026-27137.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-golang-2026-27137
Aliases
Published
2026-03-10T08:44:11Z
Modified
2026-09-16T16:45:04Z
Summary
Incorrect enforcement of email constraints in crypto/x509
Details

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.

Database specific
{
    "cpes": [
        "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / golang

Package

Name
golang
Purl
pkg:bitnami/golang

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
1.26.0-0
Fixed
1.26.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/golang/BIT-golang-2026-27137.json"