Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32281

Опубликовано: 08 апр. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

A flaw was found in Go's crypto/x509 package. A remote attacker could exploit this by presenting a specially crafted certificate chain containing a large number of policy mappings. This inefficient validation process consumes excessive resources, which can lead to a denial of service (DoS) for applications or systems performing certificate validation.

Отчет

This flaw occurs during the validation of otherwise trusted certificate chains that contain a large number of policy mappings, leading to excessive resource consumption. Exploitation requires an attacker to present a specially crafted, yet trusted, certificate chain which would require the attacker has already compromised a trusted certificate root. Red Hat continuously monitors certificate authorities and curates the set which is trusted by default for Red Hat products.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2redhat-user-workloads/applianceAffected
Builds for Red Hat OpenShiftredhat-user-workloads/openshift-builds-waiter-1-6Not affected
Builds for Red Hat OpenShiftredhat-user-workloads/openshift-builds-waiter-1-7Not affected
cert-manager Operator for Red Hat OpenShiftredhat-user-workloads/jetstack-cert-manager-1-17Affected
cert-manager Operator for Red Hat OpenShiftredhat-user-workloads/jetstack-cert-manager-1-18Affected
Confidential Compute Attestationredhat-user-workloads/osc-caaAffected
Confidential Compute Attestationredhat-user-workloads/trustee-operatorAffected
Deployment Validation Operatorredhat-user-workloads/deployment-validation-operatorAffected
ExternalDNS Operatoredo/external-dns-rhel8Affected
ExternalDNS Operatoredo/external-dns-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1050
https://bugzilla.redhat.com/show_bug.cgi?id=2456333crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation

EPSS

Процентиль: 28%
0.00355
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 7.5
nvd
4 месяца назад

Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

msrc
4 месяца назад

Inefficient policy validation in crypto/x509

CVSS3: 7.5
debian
4 месяца назад

Validating certificate chains which use policies is unexpectedly ineff ...

rocky
около 2 месяцев назад

Moderate: golang-github-openprinting-ipp-usb security update

EPSS

Процентиль: 28%
0.00355
Низкий

5.9 Medium

CVSS3