PT-2025-2692 · Google+11 · Go+11

Juho Forsén

·

Published

2025-01-16

·

Updated

2026-01-30

·

CVE-2024-45341

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Go versions up to 1.22.10/1.23.4
Description A certificate with a URI which has an IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.
Recommendations For Google Go versions up to 1.22.10/1.23.4, update to a version later than 1.22.10/1.23.4 to resolve the issue. As a temporary workaround, consider restricting the use of certificates with URIs in private PKIs until a patch is available. Avoid using IPv6 addresses with zone IDs in URIs for certificate validation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:3772
ALSA-2025:7466
ALT-PU-2025-1484
ALT-PU-2025-1742
ALT-PU-2025-1744
AZL-56031
AZL-56043
AZL-56046
AZL-78954
BDU:2025-03335
BIT-GOLANG-2024-45341
CESA-2025_3772
CLEANSTART-2026-CR41732
CLEANSTART-2026-OJ41940
CVE-2024-45341
ECHO-9504-F3B5-B586
GO-2025-3373
INFSA-2025_3772
MGASA-2025-0021
OESA-2025-1221
OESA-2025-1222
OESA-2025-1223
OESA-2025-1224
OPENSUSE-SU-2025:14693-1
OPENSUSE-SU-2025:14694-1
OPENSUSE-SU-2025:14695-1
OPENSUSE-SU-2025:14710-1
OPENSUSE-SU-2025:15030-1
OPENSUSE-SU-2025_0280-1
OPENSUSE-SU-2025_0281-1
OPENSUSE-SU-2025_0285-1
OPENSUSE-SU-2025_0297-1
OPENSUSE-SU-2025_0429-1
RHSA-2025:3772
RHSA-2025:3773
RHSA-2025:7466
RHSA-2025_3772
RHSA-2025_3773
SUSE-SU-2025:01731-1
SUSE-SU-2025:0280-1
SUSE-SU-2025:0281-1
SUSE-SU-2025:0285-1
SUSE-SU-2025:0297-1
SUSE-SU-2025:03159-1
SUSE-SU-2025:0429-1
SUSE-SU-2025:1555-1
SUSE-SU-2025_0280-1
SUSE-SU-2025_0285-1
SUSE-SU-2025_03159-1
USN-7574-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Go
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu