VDB

RHSA-2025%3A14484

RHSA-2025%3A14484 PUBLISHED CVSS 7.5 HIGH

A flaw was found in Go's crypto/x509 package. This vulnerability allows improper certificate validation, bypassing policy constraints via using ExtKeyUsageAny in VerifyOptions.KeyUsages.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Red Hatregistry.redhat.io/rhtas/rhtas-operator-bundle@sha256:7c4e739622f68cd924afcb41cc788cdadc34c725283a097e564d620f39637bac_amd64 as a component of Red Hat Trusted Artifact Signer 1.2*
Red Hatregistry.redhat.io/rhtas/rhtas-rhel9-operator@sha256:01b63201e2f0547a1a2ad4a4bfa1e3560e05a813998fb0f3e415c5adcf68b78c_amd64 as a component of Red Hat Trusted Artifact Signer 1.2*

Timeline

  • Aug 25, 2025 CVE Published
  • May 15, 2026 CVE Updated
  • May 16, 2026 Distribution Patch
  • May 16, 2026 Distribution Patch
  • May 16, 2026 Security Advisory
  • May 16, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›