CVE-2026-33810
Case-Sensitive DNS Name Constraint Bypass in Go crypto/x509
Goのcrypto/x509におけるDNS名制約検証の大文字・小文字不一致によるバイパス
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
Disclosure Date
2026/4/8
Credit
k1rnt ( @k1rnt )
Reference
・https://www.cve.org/CVERecord?id=CVE-2026-33810
・https://pkg.go.dev/vuln/GO-2026-4866
・https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU?pli=1