ZeroHour

CVE-2026-27137

CVSS 3.1
7.5 high
EPSS
<1%p47
Published
()
Modified
Description

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.

Vendors
golang
Products
go
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.