CVE-2026-27137

Source
https://cve.org/CVERecord?id=CVE-2026-27137
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-27137.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-27137
Aliases
Downstream
Related
Published
2026-03-06T21:28:13.748Z
Modified
2026-05-15T04:14:30.823059593Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Incorrect enforcement of email constraints in crypto/x509
Details

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27137.json",
    "cna_assigner": "Go",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "1.26.0-0"
                },
                {
                    "fixed": "1.26.1"
                }
            ]
        }
    ]
}
References

Affected packages