Home

Description

An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.

PUBLISHED Reserved 2025-09-30 | Published 2025-12-03 | Updated 2025-12-03 | Assigner Go

Problem types

CWE-295: Improper Certificate Validation

Product status

Default status
unaffected

Any version before 1.24.11
affected

1.25.0 (semver) before 1.25.5
affected

References

go.dev/cl/723900

go.dev/issue/76442

groups.google.com/g/golang-announce/c/8FJoBkPddm4

pkg.go.dev/vuln/GO-2025-4175

cve.org (CVE-2025-61727)

nvd.nist.gov (CVE-2025-61727)