Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33810

Опубликовано: 08 апр. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

A flaw was found in the crypto/x509 package within Go (golang). When verifying a certificate chain, excluded DNS (Domain Name System) constraints are not correctly applied to wildcard DNS Subject Alternative Names (SANs) if the case of the SAN differs from the constraint. This oversight could allow an attacker to bypass certificate validation, potentially leading to the acceptance of a malicious certificate that should have been rejected. This issue specifically impacts the validation of trusted certificate chains.

Отчет

This is an Important flaw in the Go crypto/x509 package that could allow an attacker to bypass certificate validation. The vulnerability arises from an incorrect application of excluded DNS constraints to wildcard DNS Subject Alternative Names (SANs) when their case differs from the constraint. This could lead to Red Hat products accepting malicious certificates from otherwise trusted chains, compromising the trust model.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Affected
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9-operatorWill not fix
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Will not fix
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9Not affected
Deployment Validation Operatordvo/deployment-validation-rhel8-operatorAffected
ExternalDNS Operatoredo/external-dns-rhel8Not affected
ExternalDNS Operatoredo/external-dns-rhel9Not affected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Not affected
Fence Agents Remediation Operatorworkload-availability/fence-agents-remediation-rhel8-operatorAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1289
https://bugzilla.redhat.com/show_bug.cgi?id=2456335crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application

EPSS

Процентиль: 25%
0.0034
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
6 месяцев назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 8.2
nvd
6 месяцев назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 5.9
msrc
6 месяцев назад

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

CVSS3: 8.2
debian
6 месяцев назад

When verifying a certificate chain containing excluded DNS constraints ...

CVSS3: 8.2
redos
5 месяцев назад

Уязвимость golang

EPSS

Процентиль: 25%
0.0034
Низкий

8.8 High

CVSS3