Executive brief
A security issue was identified in the Go programming language's standard library used for verifying digital certificates. When a certificate contains multiple email address restrictions that look similar (sharing the same username but different domains), the system may fail to enforce all of them, potentially allowing unauthorized email addresses to be accepted. This could allow a malicious actor with a certificate from a trusted provider to bypass specific security constraints intended to limit their authority.
Technical details
A vulnerability exists in the crypto/x509 package of the Go standard library during certificate chain validation. When a certificate contains multiple email address name constraints that share a common local portion (the part before the '@') but have different domain portions, the validation logic only applies the final constraint in the list. This flaw allows certificates containing email addresses that should be excluded or are not permitted by the intermediate constraints to be successfully returned by Certificate.Verify. The issue is specific to Go 1.26 and requires a trusted CA to issue the non-compliant certificate, as name constraint checks occur after the chain is built to a trusted root. The vulnerability was addressed in Go 1.26.1.
Affected products
- Google Go 1.26.0 to 1.26.1
Timeline
- 2026-03-04: disclosed: Issue reported to the Go project by Jakub Ciolek.
- 2026-03-06: advisory: Published as GO-2026-4599 and CVE-2026-27137.
- 2026-03-06: patched: Fixed in Go version 1.26.1.