Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
References
Configurations
History
No history.
Information
Published : 2026-05-22 04:16
Updated : 2026-09-15 12:17
NVD link : CVE-2026-42508
Mitre link : CVE-2026-42508
CVE.ORG link : CVE-2026-42508
JSON object : View
Products Affected
golang
- crypto
CWE
CWE-295
Improper Certificate Validation
