CVE-2026-33810

Case-Sensitive DNS Name Constraint Bypass in Go crypto/x509

Goのcrypto/x509におけるDNS名制約検証の大文字・小文字不一致によるバイパス

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

Disclosure Date

2026/4/8

Credit

k1rnt ( @k1rnt )

Reference

https://www.cve.org/CVERecord?id=CVE-2026-33810

https://pkg.go.dev/vuln/GO-2026-4866

https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU?pli=1