CVE-2026-27137

🟡 Monitoruj

Błąd w weryfikacji łańcucha certyfikatów ignoruje wcześniejsze ograniczenia adresów e-mail.

CVSS
7.5
EPSS
0.6%
Exploit
none
Vendor
golang
Opis źródłowy (NVD)

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.6%
Opublikowano (NVD)2026-03-06 22:16:00 UTC
Ostatnia modyfikacja (NVD)2026-08-27 13:17:14 UTC
Referencje