High severity7.5NVD Advisory· Published Mar 6, 2026· Updated Apr 21, 2026
CVE-2026-27137
CVE-2026-27137
Description
When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- pkg.go.dev/vuln/GO-2026-4599nvdVendor Advisory
- go.dev/cl/752182nvdMailing List
- go.dev/issue/77952nvdIssue Tracking
- groups.google.com/g/golang-announce/c/EdhZqrQ98hknvdRelease Notes
News mentions
0No linked articles in our index yet.