Skip to content

crypto/x509: excluded subdomain constraint doesn't preclude wildcard SAN (CVE-2025-61727) #76442

Description

@rolandshoemaker

A certificate with the excluded constraint foo.example.com should preclude a leaf with the SAN *.example.com. This unfortunately is not well defined in the X.509 specifications, so slipped through.

This is a PUBLIC track security issue.

Activity

  1. gopherbot commented on Nov 24, 2025

    @gopherbot
    Contributor

    Change https://go.dev/cl/723900 mentions this issue: crypto/x509: excluded subdomain constraints preclude wildcard SANs

  2. rolandshoemaker commented on Nov 25, 2025

    @rolandshoemaker
    MemberAuthor

    @gopherbot please open backport issues, this is a minor security bug.

  3. gopherbot commented on Nov 25, 2025

    @gopherbot
    Contributor

    Backport issue(s) opened: #76463 (for 1.24), #76464 (for 1.25).

    Remember to create the cherry-pick CL(s) as soon as the patch is submitted to master, according to https://go.dev/wiki/MinorReleases.

  4. gopherbot commented on Nov 25, 2025

    @gopherbot
    Contributor

    Change https://go.dev/cl/724400 mentions this issue: [release-branch.go1.25] crypto/x509: excluded subdomain constraints preclude wildcard SANs

  5. gopherbot commented on Nov 25, 2025

    @gopherbot
    Contributor

    Change https://go.dev/cl/724401 mentions this issue: [release-branch.go1.24] crypto/x509: excluded subdomain constraints preclude wildcard SANs

  6. added this to the Go1.26 milestone on Nov 25, 2025
  7. added
    NeedsFixThe path to resolution is known, but the work has not been done.
    on Nov 25, 2025
  8. added 2 commits that reference this issue on Nov 25, 2025
    287017a
    04db77a
  9. changed the title [-]crypto/x509: excluded subdomain constraint doesn't preclude wildcard SAN[/-] [+]crypto/x509: excluded subdomain constraint doesn't preclude wildcard SAN (CVE-2025-61727)[/+] on Dec 2, 2025
  10. dmitshur commented on Dec 2, 2025

    @dmitshur
    Member

    @rolandshoemaker Checking on the status here, what is left to resolve this issue (for Go 1.26)? Thanks.

  11. rolandshoemaker commented on Dec 2, 2025

    @rolandshoemaker
    MemberAuthor

    We landed a different fix for this than was backported (I actually meant to land this first, and then the follow-up, but it auto-submitted before I noticed). This can be closed now since there is nothing left to do for 1.26.

  12. stapelberg commented on Dec 3, 2025

    @stapelberg
    Contributor

    We landed a different fix for this than was backported (I actually meant to land this first, and then the follow-up, but it auto-submitted before I noticed). This can be closed now since there is nothing left to do for 1.26.

    Just for the record, the “different fix” is https://go.dev/cl/711421

  13. added 2 commits that reference this issue on Mar 19, 2026
    aa2bb6c
    b676504
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

FixPendingIssues that have a fix which has not yet been reviewed or submitted.NeedsFixThe path to resolution is known, but the work has not been done.Securityrelease-blocker

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions