1sealsemantic last-mile verification

Research / Finding

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

F-GO-X509-WILDCARD-CASE-001

Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

7.5high
CVE-2026-33810CVEgolang/go

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

Fixed in: go1.26.2

patched
details
Finding IDs
F-GO-X509-WILDCARD-CASE-001
CVE
CVE-2026-33810
GHSA
GHSA-fv83-x2xw-2j55
Status
patched
Fixed in
go1.26.2
Recorded credit
public credit to @1seal in golang/go#78332
Note
GHSA-fv83-x2xw-2j55
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVE registry state
PUBLISHED
CVE state checked
CVSS assessment
CISA ADP; v3.1; 7.5; observed 2026-09-24

F-GO-X509-WILDCARD-CASE-001: Verification failures. Wildcard case handling bypasses certificate name constraints; downstream receipts share this ID. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-GO-X509-WILDCARD-CASE-001

Security area (1seal assessment): Identity. Excluded certificate DNS constraints fail to cover differently cased wildcard names, weakening certificate identity validation. Reviewed 21 Sep 2026.

—score not recorded
containerd/containerd #13189Credited fixcontainerd/containerd

[release/2.1] update to Go 1.25.9, 1.26.2

merged
details
Finding IDs
F-GO-X509-WILDCARD-CASE-001
Status
merged
Recorded credit
PR body includes @1seal in the upstream Go security credit text for Go 1.25.9 / 1.26.2.
Note
merged into release/2.1 on 2026-04-08; merge commit e4244c720f20.

F-GO-X509-WILDCARD-CASE-001: Verification failures. Wildcard case handling bypasses certificate name constraints; downstream receipts share this ID. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-GO-X509-WILDCARD-CASE-001

Security area (1seal assessment): Identity. Wildcard case handling bypasses certificate name constraints; downstream receipts share this ID. Reviewed 24 Sep 2026.

—score not recorded
containerd/containerd #13190Credited fixcontainerd/containerd

[release/2.2] update to Go 1.25.9, 1.26.2

merged
details
Finding IDs
F-GO-X509-WILDCARD-CASE-001
Status
merged
Recorded credit
PR body includes @1seal in the upstream Go security credit text for Go 1.25.9 / 1.26.2.
Note
merged into release/2.2 on 2026-04-09; merge commit 17847ac84599.

F-GO-X509-WILDCARD-CASE-001: Verification failures. Wildcard case handling bypasses certificate name constraints; downstream receipts share this ID. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-GO-X509-WILDCARD-CASE-001

Security area (1seal assessment): Identity. Wildcard case handling bypasses certificate name constraints; downstream receipts share this ID. Reviewed 24 Sep 2026.

—score not recorded
testcontainers/testcontainers-go #3647Credited fixtestcontainers/testcontainers-go

chore: update to Go 1.25.9, 1.26.9

merged
details
Finding IDs
F-GO-X509-WILDCARD-CASE-001
Status
merged
Recorded credit
PR body includes @1seal in the upstream Go security credit text for Go 1.25.9 / 1.26.2.
Note
merged into main on 2026-04-09; merge commit 580abf68d440. PR title says 1.26.9, body references Go 1.26.2.

F-GO-X509-WILDCARD-CASE-001: Verification failures. Wildcard case handling bypasses certificate name constraints; downstream receipts share this ID. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-GO-X509-WILDCARD-CASE-001

Security area (1seal assessment): Identity. This downstream Go update includes the wildcard DNS-constraint fix linked to this finding; it is adoption, not a new defect or authored fix. Reviewed 21 Sep 2026.

—score not recorded
google/go-containerregistry #2255Credited fixgoogle/go-containerregistry

update to Go 1.26.2

merged
details
Finding IDs
F-GO-X509-WILDCARD-CASE-001
Status
merged
Recorded credit
PR body includes @1seal in the upstream Go security credit text for Go 1.26.2.
Note
merged into main on 2026-04-11; merge commit f8be1d442e6f.

F-GO-X509-WILDCARD-CASE-001: Verification failures. Wildcard case handling bypasses certificate name constraints; downstream receipts share this ID. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-GO-X509-WILDCARD-CASE-001

Security area (1seal assessment): Identity. This downstream Go update includes the wildcard DNS-constraint fix linked to this finding; it is adoption, not a new defect or authored fix. Reviewed 21 Sep 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.