CVE-2026-27145

Published: June 5, 2026Last modified: July 8, 2026

Description

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

Severity score breakdown

ParameterValue
Base score6.5
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactLOW
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgoFixed (1.25.11-r0)
25 LTSgoFixed (1.25.11-r0)
StreamgoFixed (1.26.4-r0)
Hardened Containers23 LTSgoFixed (1.25.11-r0)
25 LTSgoFixed (1.25.11-r0)
StreamgoFixed (1.26.4-r0)

References

ON THIS PAGE