PT-2026-31068 · Go Standard Library · Crypto/X509
1Seal
+2
·
Published
2026-04-08
·
Updated
2026-04-08
·
CVE-2026-33810
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crypto/X509