8.2 CVE-2026-33810

Enriched by CISA Patch
 

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
https://nvd.nist.gov/vuln/detail/CVE-2026-33810

Categories

CWE-295 : Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate. Certificates should be carefully managed and checked to assure that data are encrypted with the intended owner's public key. If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the hostname. A Go framework for robotics, drones, and IoT devices skips verification of root CA certificates by default. Chain: incorrect "goto" in Apple SSL product bypasses certificate validation, allowing Adversary-in-the-Middle (AITM) attack (Apple "goto fail" bug). CWE-705 (Incorrect Control Flow Scoping) -> CWE-561 (Dead Code) -> CWE-295 (Improper Certificate Validation) -> CWE-393 (Return of Wrong Status Code) -> CWE-300 (Channel Accessible by Non-Endpoint). The code's whitespace indentation did not reflect the actual control flow (CWE-1114) and did not explicitly delimit the block (CWE-483), which could have made it more difficult for human code auditors to detect the vulnerability. Chain: router's firmware update procedure uses curl with "-k" (insecure) option that disables certificate validation (CWE-295), allowing adversary-in-the-middle (AITM) compromise with a malicious firmware image (CWE-494). Verification function trusts certificate chains in which the last certificate is self-signed. Web browser uses a TLS-related function incorrectly, preventing it from verifying that a server's certificate is signed by a trusted certification authority (CA) Web browser does not check if any intermediate certificates are revoked. Operating system does not check Certificate Revocation List (CRL) in some cases, allowing spoofing using a revoked certificate. Mobile banking application does not verify hostname, leading to financial loss. Cloud-support library written in Python uses incorrect regular expression when matching hostname. Web browser does not correctly handle '' character (NUL) in Common Name, allowing spoofing of https sites. Smartphone device does not verify hostname, allowing spoofing of mail services. Application uses third-party library that does not validate hostname. Cloud storage management application does not validate hostname. Java library uses JSSE SSLSocket and SSLEngine classes, which do not verify the hostname. Chain: incorrect calculation (CWE-682) allows attackers to bypass certificate checks (CWE-295) library for SSL and TLS does not check the activation or expiration dates of CA certificates LDAP client accepts certificates even if they are not from a trusted CA. chain: DNS server does not correctly check return value from the OpenSSL EVP_VerifyFinal function allows bypass of validation of the certificate chain. chain: product checks if client is trusted when it intended to check if the server is trusted, allowing validation of signed code. Cryptographic API, as used in web browsers, mail clients, and other software, does not properly validate Basic Constraints. chain: OS package manager does not check properly check the return value, allowing bypass using a revoked certificate.

CWE-1289 : Improper Validation of Unsafe Equivalence in Input
The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value. Chain: A microservice integration and management platform compares the hostname in the HTTP Host header in a case-sensitive way (CWE-178, CWE-1289), allowing bypass of the authorization policy (CWE-863) using a hostname with mixed case or other variations. Chain: Go-based Oauth2 reverse proxy can send the authenticated user to another site at the end of the authentication flow. A redirect URL with HTML-encoded whitespace characters can bypass the validation (CWE-1289) to redirect to a malicious site (CWE-601) File extension check in forum software only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters. Task Manager does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped. HTTP server allows bypass of access restrictions using URIs with mixed case.

References

0b0ca135-0b70-47e7-9f44-1890c2a1c46c

https://access.redhat.com/errata/RHSA-2026:10155
https://access.redhat.com/errata/RHSA-2026:10158
https://access.redhat.com/errata/RHSA-2026:13545
https://access.redhat.com/errata/RHSA-2026:14391
https://access.redhat.com/errata/RHSA-2026:19135
https://access.redhat.com/errata/RHSA-2026:19144
https://access.redhat.com/errata/RHSA-2026:19353
https://access.redhat.com/errata/RHSA-2026:19719
https://access.redhat.com/errata/RHSA-2026:19720
https://access.redhat.com/errata/RHSA-2026:19721
https://access.redhat.com/errata/RHSA-2026:21769
https://access.redhat.com/errata/RHSA-2026:21772
https://access.redhat.com/errata/RHSA-2026:22347
https://access.redhat.com/errata/RHSA-2026:22485
https://access.redhat.com/errata/RHSA-2026:22862
https://access.redhat.com/errata/RHSA-2026:22958
https://access.redhat.com/errata/RHSA-2026:22959
https://access.redhat.com/errata/RHSA-2026:22960
https://access.redhat.com/errata/RHSA-2026:22961
https://access.redhat.com/errata/RHSA-2026:22962
https://access.redhat.com/errata/RHSA-2026:23345
https://access.redhat.com/errata/RHSA-2026:24478
https://access.redhat.com/errata/RHSA-2026:25089
https://access.redhat.com/errata/RHSA-2026:26568
https://access.redhat.com/errata/RHSA-2026:26571
https://access.redhat.com/errata/RHSA-2026:26585
https://access.redhat.com/errata/RHSA-2026:28047
https://access.redhat.com/errata/RHSA-2026:29854
https://access.redhat.com/errata/RHSA-2026:34192
https://access.redhat.com/errata/RHSA-2026:34196
https://access.redhat.com/errata/RHSA-2026:34197
https://access.redhat.com/errata/RHSA-2026:34365
https://access.redhat.com/errata/RHSA-2026:36651
https://access.redhat.com/errata/RHSA-2026:36796
https://access.redhat.com/errata/RHSA-2026:39810
https://access.redhat.com/errata/RHSA-2026:40118
https://access.redhat.com/errata/RHSA-2026:40945
https://access.redhat.com/errata/RHSA-2026:41928
https://access.redhat.com/errata/RHSA-2026:42043
https://access.redhat.com/errata/RHSA-2026:42047
https://access.redhat.com/errata/RHSA-2026:42049
https://access.redhat.com/errata/RHSA-2026:42050
https://access.redhat.com/errata/RHSA-2026:42051
https://access.redhat.com/errata/RHSA-2026:47952
https://access.redhat.com/errata/RHSA-2026:51033
https://access.redhat.com/errata/RHSA-2026:51288
https://access.redhat.com/errata/RHSA-2026:54757
https://access.redhat.com/errata/RHSA-2026:7291
https://access.redhat.com/errata/RHSA-2026:9385
https://access.redhat.com/security/cve/CVE-2026-33810
https://bugzilla.redhat.com/show_bug.cgi?id=2456335
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33810.json

af854a3a-2127-422b-91ae-364da2661108

security@golang.org Patch


 

AFFECTED (from MITRE)


Vendor Product Versions
Go standard library crypto/x509
  • 1.26.0-0 < 1.26.2 [affected]
© 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

CPE

cpe start end
Configuration 1
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* >= 1.26.0 < 1.26.2


REMEDIATION


Patch

Url
https://go.dev/cl/763763


EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
459 Creating a Rogue Certification Authority Certificate
Very High
475 Signature Spoofing by Improper Validation
High