Repository navigation
crypto/x509: excluded subdomain constraint doesn't preclude wildcard SAN (CVE-2025-61727) #76442
Description
Activity
Change https://go.dev/cl/723900 mentions this issue:
crypto/x509: excluded subdomain constraints preclude wildcard SANs@gopherbot please open backport issues, this is a minor security bug.
Backport issue(s) opened: #76463 (for 1.24), #76464 (for 1.25).
Remember to create the cherry-pick CL(s) as soon as the patch is submitted to master, according to https://go.dev/wiki/MinorReleases.
Change https://go.dev/cl/724400 mentions this issue:
[release-branch.go1.25] crypto/x509: excluded subdomain constraints preclude wildcard SANsChange https://go.dev/cl/724401 mentions this issue:
[release-branch.go1.24] crypto/x509: excluded subdomain constraints preclude wildcard SANs- addedNeedsFixThe path to resolution is known, but the work has not been done.The path to resolution is known, but the work has not been done.
on Nov 25, 2025 - added 2 commits that reference this issue
on Nov 25, 2025 - addedFixPendingIssues that have a fix which has not yet been reviewed or submitted.Issues that have a fix which has not yet been reviewed or submitted.
on Nov 26, 2025 - changed the title
[-]crypto/x509: excluded subdomain constraint doesn't preclude wildcard SAN[/-][+]crypto/x509: excluded subdomain constraint doesn't preclude wildcard SAN (CVE-2025-61727)[/+]on Dec 2, 2025 @rolandshoemaker Checking on the status here, what is left to resolve this issue (for Go 1.26)? Thanks.
We landed a different fix for this than was backported (I actually meant to land this first, and then the follow-up, but it auto-submitted before I noticed). This can be closed now since there is nothing left to do for 1.26.
Reacted by Dmitri ShuralyovWe landed a different fix for this than was backported (I actually meant to land this first, and then the follow-up, but it auto-submitted before I noticed). This can be closed now since there is nothing left to do for 1.26.
Just for the record, the “different fix” is https://go.dev/cl/711421
Reacted by Dmitri Shuralyov- added a commit that references this issue
on Jan 20, 2026 - added a commit that references this issue
on Jan 27, 2026 - added 2 commits that reference this issue
on Mar 19, 2026
A certificate with the excluded constraint foo.example.com should preclude a leaf with the SAN *.example.com. This unfortunately is not well defined in the X.509 specifications, so slipped through.
This is a PUBLIC track security issue.