Research / Finding
Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509 F-GO-X509-WILDCARD-CASE-001
Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.
Read the evidence · View in research browse
Recorded evidence
7.5high
Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
Fixed in: go1.26.2
patched
details
Finding IDs F-GO-X509-WILDCARD-CASE-001 CVE CVE-2026-33810 GHSA GHSA-fv83-x2xw-2j55 Status patched Fixed in go1.26.2 Recorded credit public credit to @1seal in golang/go#78332 Note GHSA-fv83-x2xw-2j55 CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE registry state PUBLISHED CVE state checked 23 Sep 2026 CVSS assessment CISA ADP; v3.1; 7.5; observed 2026-09-24 F-GO-X509-WILDCARD-CASE-001: Verification failures. Wildcard case handling bypasses certificate name constraints; downstream receipts share this ID. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-GO-X509-WILDCARD-CASE-001
Security area (1seal assessment): Identity. Excluded certificate DNS constraints fail to cover differently cased wildcard names, weakening certificate identity validation. Reviewed 21 Sep 2026.
—score not recorded
[release/2.1] update to Go 1.25.9, 1.26.2
merged
details
Finding IDs F-GO-X509-WILDCARD-CASE-001 Status merged Recorded credit PR body includes @1seal in the upstream Go security credit text for Go 1.25.9 / 1.26.2. Note merged into release/2.1 on 2026-04-08; merge commit e4244c720f20. F-GO-X509-WILDCARD-CASE-001: Verification failures. Wildcard case handling bypasses certificate name constraints; downstream receipts share this ID. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-GO-X509-WILDCARD-CASE-001
Security area (1seal assessment): Identity. Wildcard case handling bypasses certificate name constraints; downstream receipts share this ID. Reviewed 24 Sep 2026.
—score not recorded
[release/2.2] update to Go 1.25.9, 1.26.2
merged
details
Finding IDs F-GO-X509-WILDCARD-CASE-001 Status merged Recorded credit PR body includes @1seal in the upstream Go security credit text for Go 1.25.9 / 1.26.2. Note merged into release/2.2 on 2026-04-09; merge commit 17847ac84599. F-GO-X509-WILDCARD-CASE-001: Verification failures. Wildcard case handling bypasses certificate name constraints; downstream receipts share this ID. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-GO-X509-WILDCARD-CASE-001
Security area (1seal assessment): Identity. Wildcard case handling bypasses certificate name constraints; downstream receipts share this ID. Reviewed 24 Sep 2026.
—score not recorded
chore: update to Go 1.25.9, 1.26.9
merged
details
Finding IDs F-GO-X509-WILDCARD-CASE-001 Status merged Recorded credit PR body includes @1seal in the upstream Go security credit text for Go 1.25.9 / 1.26.2. Note merged into main on 2026-04-09; merge commit 580abf68d440. PR title says 1.26.9, body references Go 1.26.2. F-GO-X509-WILDCARD-CASE-001: Verification failures. Wildcard case handling bypasses certificate name constraints; downstream receipts share this ID. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-GO-X509-WILDCARD-CASE-001
Security area (1seal assessment): Identity. This downstream Go update includes the wildcard DNS-constraint fix linked to this finding; it is adoption, not a new defect or authored fix. Reviewed 21 Sep 2026.
—score not recorded
merged
details
Finding IDs F-GO-X509-WILDCARD-CASE-001 Status merged Recorded credit PR body includes @1seal in the upstream Go security credit text for Go 1.26.2. Note merged into main on 2026-04-11; merge commit f8be1d442e6f. F-GO-X509-WILDCARD-CASE-001: Verification failures. Wildcard case handling bypasses certificate name constraints; downstream receipts share this ID. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-GO-X509-WILDCARD-CASE-001
Security area (1seal assessment): Identity. This downstream Go update includes the wildcard DNS-constraint fix linked to this finding; it is adoption, not a new defect or authored fix. Reviewed 21 Sep 2026.
Clarify or correct this record privately . The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy .
How this page groups evidence This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules .