VDB

RHSA-2026%3A19715

RHSA-2026%3A19715 PUBLISHED CVSS 7.5 HIGH

A flaw was found in the Go standard library packages `crypto/x509` and `crypto/tls`. During the process of building a certificate chain, an attacker can provide a large number of intermediate certificates. This excessive input is not properly limited, leading to an uncontrolled amount of work being performed. This can result in a denial of service (DoS) condition, making the affected system or application unavailable to legitimate users.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatgit-lfs-debuginfo-0:3.6.1-2.el10_0.4.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)3.6.1-2.el10, 3.6.1-2.el10, 3.6.1-2.el10
Red Hatgit-lfs-debugsource-0:3.6.1-2.el10_0.4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)3.6.1-2.el10, 3.6.1-2.el10, 3.6.1-2.el10
golanggo
Red Hatgit-lfs-0:3.6.1-2.el10_0.4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)3.6.1-2.el10, 3.6.1-2.el10, 3.6.1-2.el10
Red Hatgit-lfs-0:3.6.1-2.el10_0.4.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)3.6.1-2.el10, 3.6.1-2.el10, 3.6.1-2.el10
Gogo
Red Hatgit-lfs-0:3.6.1-2.el10_0.4.src as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)3.6.1-2.el10, 3.6.1-2.el10, 3.6.1-2.el10
Red Hatgit-lfs-debuginfo-0:3.6.1-2.el10_0.4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)3.6.1-2.el10, 3.6.1-2.el10, 3.6.1-2.el10
Red Hatgit-lfs-debugsource-0:3.6.1-2.el10_0.4.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)3.6.1-2.el10, 3.6.1-2.el10, 3.6.1-2.el10
Red Hatgit-lfs-debuginfo-0:3.6.1-2.el10_0.4.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)3.6.1-2.el10, 3.6.1-2.el10, 3.6.1-2.el10
Red Hatgit-lfs
Red Hatgit-lfs-debugsource-0:3.6.1-2.el10_0.4.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)3.6.1-2.el10, 3.6.1-2.el10, 3.6.1-2.el10
Red Hatgit-lfs-debuginfo-0:3.6.1-2.el10_0.4.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)3.6.1-2.el10, 3.6.1-2.el10, 3.6.1-2.el10
Red Hatgit-lfs-debugsource-0:3.6.1-2.el10_0.4.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)3.6.1-2.el10, 3.6.1-2.el10, 3.6.1-2.el10
Red Hatgit-lfs-0:3.6.1-2.el10_0.4.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)3.6.1-2.el10, 3.6.1-2.el10, 3.6.1-2.el10
Red Hatgit-lfs-0:3.6.1-2.el10_0.4.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)3.6.1-2.el10, 3.6.1-2.el10, 3.6.1-2.el10

Timeline

  • May 20, 2026 CVE Published
  • May 28, 2026 Distribution Patch
  • Jun 5, 2026 Security Advisory
  • Jun 12, 2026 Security Advisory
  • Jun 12, 2026 Security Advisory
  • Jun 23, 2026 CVE Updated
  • Jun 23, 2026 Distribution Patch
  • Jun 23, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›