Количество 197
Количество 197
RLSA-2026:38995
Important: go-toolset:rhel8 security, bug fix, and enhancement update
ELSA-2026-38995
ELSA-2026-38995: go-toolset:ol8 security, bug fix, and enhancement update (IMPORTANT)
RLSA-2026:46395
Important: go-fdo-server security update
ELSA-2026-46395
ELSA-2026-46395: go-fdo-server security update (IMPORTANT)
RLSA-2026:39573
Important: yggdrasil security update
ELSA-2026-39573
ELSA-2026-39573: yggdrasil security update (IMPORTANT)
SUSE-SU-2026:3102-1
Security update for go1.26-openssl
SUSE-SU-2026:3047-1
Security update for go1.26-openssl
RLSA-2026:34359
Important: opentelemetry-collector security update
RLSA-2026:34357
Important: opentelemetry-collector security update
RLSA-2026:37436
Important: golang security, bug fix, and enhancement update
RLSA-2026:37435
Important: golang security, bug fix, and enhancement update
ELSA-2026-37436
ELSA-2026-37436: golang security, bug fix, and enhancement update (IMPORTANT)
ELSA-2026-37435
ELSA-2026-37435: golang security, bug fix, and enhancement update (IMPORTANT)
SUSE-SU-2026:3151-1
Security update for go1.25-openssl
SUSE-SU-2026:3046-1
Security update for go1.25-openssl
CVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
CVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
CVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
CVE-2026-27145
Inefficient candidate hostname parsing in crypto/x509
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:38995 Important: go-toolset:rhel8 security, bug fix, and enhancement update | 2 месяца назад | |||
ELSA-2026-38995 ELSA-2026-38995: go-toolset:ol8 security, bug fix, and enhancement update (IMPORTANT) | 2 месяца назад | |||
RLSA-2026:46395 Important: go-fdo-server security update | около 2 месяцев назад | |||
ELSA-2026-46395 ELSA-2026-46395: go-fdo-server security update (IMPORTANT) | около 2 месяцев назад | |||
RLSA-2026:39573 Important: yggdrasil security update | 2 месяца назад | |||
ELSA-2026-39573 ELSA-2026-39573: yggdrasil security update (IMPORTANT) | 2 месяца назад | |||
SUSE-SU-2026:3102-1 Security update for go1.26-openssl | около 2 месяцев назад | |||
SUSE-SU-2026:3047-1 Security update for go1.26-openssl | 2 месяца назад | |||
RLSA-2026:34359 Important: opentelemetry-collector security update | 2 месяца назад | |||
RLSA-2026:34357 Important: opentelemetry-collector security update | 2 месяца назад | |||
RLSA-2026:37436 Important: golang security, bug fix, and enhancement update | 2 месяца назад | |||
RLSA-2026:37435 Important: golang security, bug fix, and enhancement update | 2 месяца назад | |||
ELSA-2026-37436 ELSA-2026-37436: golang security, bug fix, and enhancement update (IMPORTANT) | 2 месяца назад | |||
ELSA-2026-37435 ELSA-2026-37435: golang security, bug fix, and enhancement update (IMPORTANT) | 2 месяца назад | |||
SUSE-SU-2026:3151-1 Security update for go1.25-openssl | около 2 месяцев назад | |||
SUSE-SU-2026:3046-1 Security update for go1.25-openssl | 2 месяца назад | |||
CVE-2026-27145 (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-27145 (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-27145 (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-27145 Inefficient candidate hostname parsing in crypto/x509 | 1% Низкий | 3 месяца назад |
Уязвимостей на страницу