FlawAtlas
Search the atlas
CVE-2026-27137 High

Incorrect enforcement of email constraints in crypto/x509

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.

Exploit probability 0.6%
Published March 6, 2026
Required by Not available
Last source change August 14, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go stdlib
Bitnami golang
Unknown Unknown

2 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-27137

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.

View original source
Open Source Vulnerabilities BIT-golang-2026-27137

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.

View original source
Open Source Vulnerabilities GO-2026-4599

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.

View original source

05 / REFERENCES

Further evidence