When verifying a certificate chain containing excluded...
High severity
Unreviewed
Published
Apr 8, 2026
to the GitHub Advisory Database
•
Updated Apr 20, 2026
Description
Published by the National Vulnerability Database
Apr 8, 2026
Published to the GitHub Advisory Database
Apr 8, 2026
Last updated
Apr 20, 2026
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
References