CVE-2026-32280 PUBLISHED

Unexpected work during chain building in crypto/x509

Assigner: Go
Reserved: 11.03.2026 Published: 08.04.2026 Updated: 08.04.2026

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.

Product Status

Vendor Go standard library
Product crypto/x509
Versions Default: unaffected
  • affected from 0 to 1.25.9 (excl.)
  • affected from 1.26.0-0 to 1.26.2 (excl.)

Credits

  • Jakub Ciolek - https://ciolek.dev

References

Problem Types

  • CWE-770: Allocation of Resources Without Limits or Throttling