Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

crypto/x509 — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in crypto/x509, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for the crypto/x509 library, covering the Common Weakness Enumeration (CWE) taxonomy and associated Common Vulnerabilities and Exposures (CVE) tags. It compiles security issues affecting the x.509 public key infrastructure implementation, including flaws in certificate parsing, validation logic errors, and cryptographic implementation weaknesses that may lead to authentication bypass or data exposure. The collection spans vulnerability disclosures and advisory updates over the past several years, capturing both critical and medium-severity findings that have been publicly acknowledged or patched. Here, you can track a vendor’s security advisories related to this specific component, understand the broader context of a weakness class by observing recurring patterns across different implementations, and look up a product's vulnerability history to assess long-term maintenance quality and risk trends. The data is organized to facilitate quick analysis for security researchers, developers, and auditors who need to evaluate the current threat landscape surrounding this widely used cryptographic primitive. By centralizing these records, the page serves as a reference for identifying recurring defects in certificate handling and validating compliance with modern security standards. Users can cross-reference findings with upstream patches to determine the efficacy of current mitigations and identify potential gaps in their own deployment configurations. This resource does not provide real-time monitoring or automated patching capabilities but rather offers a static historical record for risk assessment and forensic analysis.

Vendor: Go standard library

CVE IDTitleCVSSSeverityPublished
CVE-2026-27145 Inefficient candidate hostname parsing in crypto/x509 --2026-06-02
CVE-2026-32280 Unexpected work during chain building in crypto/x509 7.5AIHighAI2026-04-08
CVE-2026-32281 Inefficient policy validation in crypto/x509 7.5AIHighAI2026-04-08
CVE-2026-33810 Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509 6.5AIMediumAI2026-04-08
CVE-2026-27138 Panic in name constraint checking for malformed certificates in crypto/x509 7.5 -2026-03-06
CVE-2026-27137 Incorrect enforcement of email constraints in crypto/x509 5.3 -2026-03-06
CVE-2025-61727 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509 9.8AICriticalAI2025-12-03
CVE-2025-61729 Excessive resource consumption when printing error string for host certificate validation in crypto/x509 7.5AIHighAI2025-12-02
CVE-2025-58188 Panic when validating certificates with DSA public keys in crypto/x509 7.5AIHighAI2025-10-29
CVE-2025-58187 Quadratic complexity when checking name constraints in crypto/x509 5.3AIMediumAI2025-10-29
CVE-2025-22874 Usage of ExtKeyUsageAny disables policy validation in crypto/x509 6.5AIMediumAI2025-06-11
CVE-2025-22865 ParsePKCS1PrivateKey panic with partial keys in crypto/x509 7.5 -2025-01-28
CVE-2024-45341 Usage of IPv6 zone IDs can bypass URI name constraints in crypto/x509 5.3 -2025-01-28
CVE-2024-24783 Verify panics on certificates with an unknown public key algorithm in crypto/x509 7.5AIHighAI2024-03-05

All 14 known CVE vulnerabilities affecting crypto/x509 with full Chinese analysis, references, and POCs where available.