CVE-2026-32281

Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-08 02:16

Updated : 2026-07-25 10:10


NVD link : CVE-2026-32281

Mitre link : CVE-2026-32281

CVE.ORG link : CVE-2026-32281


JSON object : View

Products Affected

golang

  • go
CWE
CWE-295

Improper Certificate Validation