Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33810

Опубликовано: 08 апр. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

A flaw was found in the crypto/x509 package within Go (golang). When verifying a certificate chain, excluded DNS (Domain Name System) constraints are not correctly applied to wildcard DNS Subject Alternative Names (SANs) if the case of the SAN differs from the constraint. This oversight could allow an attacker to bypass certificate validation, potentially leading to the acceptance of a malicious certificate that should have been rejected. This issue specifically impacts the validation of trusted certificate chains.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Affected
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9-operatorAffected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Affected
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9Not affected
Deployment Validation Operatordvo/deployment-validation-rhel8-operatorAffected
ExternalDNS Operatoredo/external-dns-rhel8Not affected
ExternalDNS Operatoredo/external-dns-rhel9Not affected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Not affected
Fence Agents Remediation Operatorworkload-availability/fence-agents-remediation-rhel8-operatorAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1289
https://bugzilla.redhat.com/show_bug.cgi?id=2456335crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application

EPSS

Процентиль: 17%
0.00262
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
3 месяца назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 8.2
nvd
3 месяца назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 5.9
msrc
3 месяца назад

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

CVSS3: 8.2
debian
3 месяца назад

When verifying a certificate chain containing excluded DNS constraints ...

CVSS3: 7.5
github
3 месяца назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

EPSS

Процентиль: 17%
0.00262
Низкий

8.8 High

CVSS3