CVE-2026-32281

Published: April 9, 2026Last modified: April 11, 2026

Description

Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgoFixed (1.25.9-r0)
25 LTSgoFixed (1.25.9-r0)
StreamgoFixed (1.26.2-r0)
Hardened Containers23 LTSgoFixed (1.25.9-r0)
25 LTSgoFixed (1.25.9-r0)
StreamgoFixed (1.26.2-r0)

References

ON THIS PAGE