GHSA-fv83-x2xw-2j55HighCVSS 7.5

When verifying a certificate chain containing excluded DNS constraints, these constraints are not...

Published
April 8, 2026
Last Modified
August 14, 2026

🔗 CVE IDs covered (1)

📋 Description

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

🔗 References (56)