CVE-2026-27137

HIGH

OpenSSL - Certificate Validation Bypass

Title source: llm
STIX 2.1

Description

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.

Scores

CVSS v3 7.5
EPSS 0.0001
EPSS Percentile 3.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (2)
Go standard library/crypto/x509 1.26.0-0 - 1.26.1
golang/go 1.26.0
Published Mar 06, 2026
Tracked Since Mar 07, 2026