CVE-2026-27137
Go standard library crypto/x509, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support
When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.
- CVSS
- 7.5
- EPSS
- 0.61% 45.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.03.07