GO-2026-4866

    Dashboard / Vulnerabilities / GO-2026-4866

    GO-2026-4866

    Published: 7 Apr 2026Last Modified: 10 Sept 2026

    Summary: Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

    Details: When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

    Affected packages

    Package

    Name: stdlib

    Purl: pkg:golang/stdlib

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 1.26.0-0
    Fixed -1.26.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High