High severity7.5NVD Advisory· Published Apr 8, 2026· Updated Apr 16, 2026
CVE-2026-32280
CVE-2026-32280
Description
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- go.dev/cl/758320nvdPatch
- pkg.go.dev/vuln/GO-2026-4947nvdVendor Advisory
- go.dev/issue/78282nvdIssue Tracking
- groups.google.com/g/golang-announce/c/0uYbvbPZRWUnvdRelease NotesMailing List
News mentions
0No linked articles in our index yet.