boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-33810

Go standard library crypto/x509 — Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  L  N    8.2   .0034   25.2     —
AFFECTED
  Product      Versions    Fixed
  crypto/x509  1.26.0-0 –  —
TIMELINE
  Mar 23  Reserved by Go
  Apr 8   Published (CNA: Go)
  Aug 24  RESCORED — CVE-2026-33810 (Go standard library crypto/x509). CVSS 7.5 → 8.2 (NVD).
CWE-295, CWE-1289 · CNA: Go · CVSS v3.1 · 87 references · NVD status: Modified

Description

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
March 23, 2026ReservedReserved by Go
April 8, 2026PublishedPublished (CNA: Go)
August 24, 2026RESCOREDRESCORED — CVE-2026-33810 (Go standard library crypto/x509). CVSS 7.5 → 8.2 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
Go standard librarycrypto/x509—1.26.0-0—

Weaknesses

CWE-295 · CWE-1289

References (87)

Related

Authoritative record: CVE-2026-33810 at cve.org

Vendors: go standard library

Weaknesses: CWE-295 · CWE-1289

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-33810 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.