Junglewise Threat Intelligence

CVE-2026-33810: Google Go crypto/x509 improper DNS constraint validation

CVE-2026-33810 · Severity: high · CVSS 8.2 · Published 2026-04-08

Technologies: go (Go), stdlib (Go). Vendors: Go, Google.

Executive brief

A vulnerability exists in the Go programming language's standard library used for verifying digital certificates. When a security policy is set to exclude certain domain names, the library fails to enforce these restrictions if the domain name uses a mix of uppercase and lowercase letters or includes a wildcard (like *.example.com). This could allow a malicious actor to use a certificate that should have been blocked, potentially leading to unauthorized access or the interception of sensitive data.

Technical details

A vulnerability in the crypto/x509 package of the Go standard library (specifically Go 1.26) causes excluded DNS constraints to be bypassed. The root cause is an improper validation of equivalence (CWE-1289) where the library fails to correctly apply constraints to wildcard DNS Subject Alternative Names (SANs) when there is a case mismatch between the constraint and the SAN (e.g., 'EXAMPLE.COM' vs '*.example.com'). An attacker with a certificate issued by a trusted root CA can bypass name constraints intended to restrict the CA's scope. This affects certificate chains validated using VerifyOptions.Roots or the system certificate pool. The issue is fixed in Go 1.26.2.

Affected products

  • Google Go 1.26.0 to 1.26.1

Timeline

  • 2026-03-24: disclosed: Issue opened on Go GitHub repository
  • 2026-04-07: advisory: Go project published vulnerability report GO-2026-4866
  • 2026-04-08: patched: Go 1.26.2 released to address the issue

References

Related threats