When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://www.openwall.com/lists/oss-security/2026/04/19/4 cve-icon
http://www.openwall.com/lists/oss-security/2026/04/20/1 cve-icon
https://access.redhat.com/errata/RHSA-2026:10155 cve-icon
https://access.redhat.com/errata/RHSA-2026:10158 cve-icon
https://access.redhat.com/errata/RHSA-2026:13545 cve-icon
https://access.redhat.com/errata/RHSA-2026:14391 cve-icon
https://access.redhat.com/errata/RHSA-2026:19135 cve-icon
https://access.redhat.com/errata/RHSA-2026:19144 cve-icon
https://access.redhat.com/errata/RHSA-2026:19353 cve-icon
https://access.redhat.com/errata/RHSA-2026:19719 cve-icon
https://access.redhat.com/errata/RHSA-2026:19720 cve-icon
https://access.redhat.com/errata/RHSA-2026:19721 cve-icon
https://access.redhat.com/errata/RHSA-2026:21769 cve-icon
https://access.redhat.com/errata/RHSA-2026:21772 cve-icon
https://access.redhat.com/errata/RHSA-2026:22347 cve-icon
https://access.redhat.com/errata/RHSA-2026:22485 cve-icon
https://access.redhat.com/errata/RHSA-2026:22862 cve-icon
https://access.redhat.com/errata/RHSA-2026:22958 cve-icon
https://access.redhat.com/errata/RHSA-2026:22959 cve-icon
https://access.redhat.com/errata/RHSA-2026:22960 cve-icon
https://access.redhat.com/errata/RHSA-2026:22961 cve-icon
https://access.redhat.com/errata/RHSA-2026:22962 cve-icon
https://access.redhat.com/errata/RHSA-2026:23345 cve-icon
https://access.redhat.com/errata/RHSA-2026:24478 cve-icon
https://access.redhat.com/errata/RHSA-2026:25089 cve-icon
https://access.redhat.com/errata/RHSA-2026:26568 cve-icon
https://access.redhat.com/errata/RHSA-2026:26571 cve-icon
https://access.redhat.com/errata/RHSA-2026:26585 cve-icon
https://access.redhat.com/errata/RHSA-2026:28047 cve-icon
https://access.redhat.com/errata/RHSA-2026:29854 cve-icon
https://access.redhat.com/errata/RHSA-2026:34365 cve-icon
https://access.redhat.com/errata/RHSA-2026:36651 cve-icon
https://access.redhat.com/errata/RHSA-2026:36796 cve-icon
https://access.redhat.com/errata/RHSA-2026:39810 cve-icon
https://access.redhat.com/errata/RHSA-2026:40118 cve-icon
https://access.redhat.com/errata/RHSA-2026:40945 cve-icon
https://access.redhat.com/errata/RHSA-2026:41928 cve-icon
https://access.redhat.com/errata/RHSA-2026:42043 cve-icon
https://access.redhat.com/errata/RHSA-2026:42047 cve-icon
https://access.redhat.com/errata/RHSA-2026:42049 cve-icon
https://access.redhat.com/errata/RHSA-2026:42050 cve-icon
https://access.redhat.com/errata/RHSA-2026:42051 cve-icon
https://access.redhat.com/errata/RHSA-2026:47952 cve-icon
https://access.redhat.com/errata/RHSA-2026:51033 cve-icon
https://access.redhat.com/errata/RHSA-2026:7291 cve-icon
https://access.redhat.com/errata/RHSA-2026:9385 cve-icon
https://access.redhat.com/security/cve/CVE-2026-33810 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2456335 cve-icon
https://go.dev/cl/763763 cve-icon cve-icon cve-icon
https://go.dev/issue/78332 cve-icon cve-icon cve-icon
https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-33810 cve-icon
https://pkg.go.dev/vuln/GO-2026-4866 cve-icon cve-icon cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33810.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-33810 cve-icon
History

Mon, 20 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
References

Sun, 19 Apr 2026 23:30:00 +0000

Type Values Removed Values Added
References

Fri, 17 Apr 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Golang
Golang go
Weaknesses CWE-295
CPEs cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
Vendors & Products Golang
Golang go

Tue, 14 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295

Tue, 14 Apr 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1289
References
Metrics threat_severity

None

threat_severity

Important


Mon, 13 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Go Standard Library
Go Standard Library crypto/x509
Vendors & Products Go Standard Library
Go Standard Library crypto/x509

Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295

Wed, 08 Apr 2026 01:45:00 +0000

Type Values Removed Values Added
Description When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
Title Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-08-12T12:04:53.927Z

Reserved: 2026-03-23T20:35:32.814Z

Link: CVE-2026-33810

cve-icon Vulnrichment

Updated: 2026-04-20T17:23:21.823Z

cve-icon NVD

Status : Modified

Published: 2026-04-08T02:16:03.950

Modified: 2026-08-10T13:18:55.903

Link: CVE-2026-33810

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-08T01:06:56Z

Links: CVE-2026-33810 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T17:30:05Z

Weaknesses