CVE-2026-27138
Estado: AnalizadaMedia (5.9)—
Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the chain has excluded name constraints. This can crash programs that are either directly verifying X.509 certificate chains, or those that use TLS.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 24
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-295
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-27138",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-27138",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-03-10T13:34:15.972110Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "security@golang.org",
"affectedData": [
{
"vendor": "Go standard library",
"product": "crypto/x509",
"versions": [
{
"status": "affected",
"version": "1.26.0-0",
"lessThan": "1.26.1",
"versionType": "semver"
}
],
"packageName": "crypto/x509",
"collectionURL": "https://pkg.go.dev",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "dnsConstraints.query"
},
{
"name": "Certificate.Verify"
}
]
}
]
}
],
"published": "2026-03-06T22:16:00.963",
"references": [
{
"url": "https://go.dev/cl/752183",
"tags": [
"Mailing List"
],
"source": "security@golang.org"
},
{
"url": "https://go.dev/issue/77953",
"tags": [
"Issue Tracking"
],
"source": "security@golang.org"
},
{
"url": "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk",
"tags": [
"Release Notes"
],
"source": "security@golang.org"
},
{
"url": "https://pkg.go.dev/vuln/GO-2026-4600",
"tags": [
"Vendor Advisory"
],
"source": "security@golang.org"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-295"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the chain has excluded name constraints. This can crash programs that are either directly verifying X.509 certificate chains, or those that use TLS."
},
{
"lang": "es",
"value": "La verificación de certificados puede entrar en pánico cuando un certificado en la cadena tiene un nombre DNS vacío y otro certificado en la cadena tiene restricciones de nombre excluidas. Esto puede bloquear programas que están verificando directamente cadenas de certificados X.509, o aquellos que usan TLS."
}
],
"lastModified": "2026-06-17T10:26:44.093",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:golang:go:1.26.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A40FE3CB-0D03-462B-8A19-4DF1920ABE82"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@golang.org"
}