VDB

DEBIAN-CVE-2026-27137

DEBIAN-CVE-2026-27137 PUBLISHED CVSS 7.5 HIGH

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:14golang-1.261.26.0-1, 1.26~rc2-1, 1.26~rc3-1

Timeline

  • Mar 6, 2026 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›