ZeroHour

CVE-2026-27138

CVSS 3.1
5.9 medium
EPSS
<1%p28
Published
()
Modified
Description

Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the chain has excluded name constraints. This can crash programs that are either directly verifying X.509 certificate chains, or those that use TLS.

Vendors
golang
Products
go
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.