Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

crypto/x509 — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in crypto/x509, with AI-generated Chinese analysis, references, and POCs.

The vulnerability aggregation page for the crypto/x509 product catalogs known security weaknesses associated with this cryptographic implementation library. This resource compiles a comprehensive collection of vulnerabilities, including improper certificate validation, insecure key management flaws, and parsing errors, covering reports from inception through the most recent patches. By utilizing this aggregated data, users can effectively track vendor advisories to stay informed about critical updates and security notices. Furthermore, the page provides detailed context to help developers understand specific weakness classes, such as those defined in the Common Weakness Enumeration, allowing for more informed risk assessments. Readers can also look up the product’s complete vulnerability history to identify recurring patterns or systemic issues that may persist across different versions. This centralized view supports security professionals and auditors in conducting thorough reviews without needing to cross-reference multiple disparate sources. The information presented is intended to facilitate better decision-making regarding library updates and mitigation strategies. It serves as a technical reference for understanding the landscape of known defects within the x509 certificate processing logic. By consolidating these details, the page aims to reduce the overhead of security research and enable faster remediation of identified threats. Users are encouraged to review the entries carefully to apply appropriate fixes to their systems.

Vendor: Go standard library

CVE IDTitleCVSSSeverityPublished
CVE-2026-27145 Inefficient candidate hostname parsing in crypto/x509 --2026-06-02
CVE-2026-32280 Unexpected work during chain building in crypto/x509 7.5AIHighAI2026-04-08
CVE-2026-32281 Inefficient policy validation in crypto/x509 7.5AIHighAI2026-04-08
CVE-2026-33810 Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509 6.5AIMediumAI2026-04-08
CVE-2026-27138 Panic in name constraint checking for malformed certificates in crypto/x509 7.5 -2026-03-06
CVE-2026-27137 Incorrect enforcement of email constraints in crypto/x509 5.3 -2026-03-06
CVE-2025-61727 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509 9.8AICriticalAI2025-12-03
CVE-2025-61729 Excessive resource consumption when printing error string for host certificate validation in crypto/x509 7.5AIHighAI2025-12-02
CVE-2025-58188 Panic when validating certificates with DSA public keys in crypto/x509 7.5AIHighAI2025-10-29
CVE-2025-58187 Quadratic complexity when checking name constraints in crypto/x509 5.3AIMediumAI2025-10-29
CVE-2025-22874 Usage of ExtKeyUsageAny disables policy validation in crypto/x509 6.5AIMediumAI2025-06-11
CVE-2025-22865 ParsePKCS1PrivateKey panic with partial keys in crypto/x509 7.5 -2025-01-28
CVE-2024-45341 Usage of IPv6 zone IDs can bypass URI name constraints in crypto/x509 5.3 -2025-01-28
CVE-2024-24783 Verify panics on certificates with an unknown public key algorithm in crypto/x509 7.5AIHighAI2024-03-05

All 14 known CVE vulnerabilities affecting crypto/x509 with full Chinese analysis, references, and POCs where available.