CVE-2026-27137
גבוהה 7.5
תיאור (מקור, אנגלית)
When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 1% (אחוזון 000) נכון ל-26/7/2026
- CWE
- CWE-295
מוצרים מושפעים
golang: go
קישורים
- https://pkg.go.dev/vuln/GO-2026-4599 Vendor Advisory
- https://go.dev/cl/752182 Mailing List
- https://go.dev/issue/77952 Issue Tracking
- https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk Release Notes
- https://access.redhat.com/errata/RHSA-2026:10125
- https://access.redhat.com/errata/RHSA-2026:10158
- https://access.redhat.com/errata/RHSA-2026:10169
- https://access.redhat.com/errata/RHSA-2026:10175
- https://access.redhat.com/errata/RHSA-2026:10184
- https://access.redhat.com/errata/RHSA-2026:10225