Go <1.26: crypto/x509 Email Constraint Bug
CVE-2026-27137 Published on March 6, 2026
Incorrect enforcement of email constraints in crypto/x509
When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.
Vulnerability Analysis
CVE-2026-27137 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Privileges Required:
NONE
Confidentiality Impact:
NONE
Availability Impact:
HIGH
Weakness Type
Improper Certificate Validation
The software does not validate, or incorrectly validates, a certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.
Products Associated with CVE-2026-27137
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
Go standard library
crypto/x509:
-
Version 1.26.0-0 and below 1.26.1
is affected.
Red Hat Enterprise Linux 10:
-
Version 0:0.2.3-4.el10_1 and below *
is unaffected.
-
Version 0:0.2.7-3.el10_2 and below *
is unaffected.
Red Hat Enterprise Linux 10:
-
Version 0:1.25.2-3.el10_1 and below *
is unaffected.
Red Hat Enterprise Linux 10:
-
Version 0:1.26.2-2.el10_2 and below *
is unaffected.
Red Hat Enterprise Linux 10:
-
Version 0:0.9.27-6.el10_2 and below *
is unaffected.
Red Hat Enterprise Linux 10:
-
Version 0:165.1-2.el10_2 and below *
is unaffected.
Red Hat Enterprise Linux 10:
-
Version 0:52.1-1.el10_2 and below *
is unaffected.
Red Hat Enterprise Linux 10.0 Extended Update Support:
-
Version 0:0.2.3-4.el10_0 and below *
is unaffected.
Red Hat Enterprise Linux 9:
-
Version 0:1.26.2-1.el9_8 and below *
is unaffected.
Red Hat Enterprise Linux 9:
-
Version 0:165.1-2.el9_8 and below *
is unaffected.
Red Hat Enterprise Linux 9:
-
Version 0:52.1-1.el9_8 and below *
is unaffected.
Red Hat Enterprise Linux 9.6 Extended Update Support:
-
Version 6:0.8.5-2.el9_6.2 and below *
is unaffected.
Red Hat OpenStack Platform 17.1 for RHEL 9:
-
Version 0:3.4.26-9.5.el9ost and below *
is unaffected.
Red Hat OpenStack Services on OpenShift 18.0:
-
Version 0:0.1.1-18.0.20260602234716.a95ae05.el9ost and below *
is unaffected.
Red Hat
RHEM 1.0 for RHEL 9:
-
Version 0:1.0.3-1.el9em and below *
is unaffected.
Red Hat
RHEM 1.1 for RHEL 10:
-
Version 0:1.1.3-1.el10em and below *
is unaffected.
Red Hat
RHEM 1.1 for RHEL 9:
-
Version 0:1.1.3-1.el9em and below *
is unaffected.
Builds for Red Hat OpenShift 1.6.0:
-
Version 1774334066 and below *
is unaffected.
Red Hat
DevWorkspace Operator 0.4:
-
Version 1776457293 and below *
is unaffected.
Logging Subsystem for Red Hat OpenShift 6.0:
-
Version 1781192891 and below *
is unaffected.
Logging Subsystem for Red Hat OpenShift 6.2:
-
Version 1776800087 and below *
is unaffected.
Logging Subsystem for Red Hat OpenShift 6.4:
-
Version 1780051640 and below *
is unaffected.
Red Hat
Multicluster Global Hub 1.3.4:
-
Version 1779210675 and below *
is unaffected.
Red Hat
Multicluster Global Hub 1.5.4:
-
Version 1773650627 and below *
is unaffected.
-
Version 1779828691 and below *
is unaffected.
Red Hat
Multicluster Global Hub 1.6.2:
-
Version 1780320809 and below *
is unaffected.
Red Hat
OpenShift API for Data Protection 1.4:
-
Version 1779809598 and below *
is unaffected.
Red Hat
OpenShift API for Data Protection 1.5:
-
Version 1779808027 and below *
is unaffected.
Red Hat Advanced Cluster Management for Kubernetes 2.15:
-
Version 1774085848 and below *
is unaffected.
Red Hat Ansible Automation Platform 2.6:
-
Version 1777391542 and below *
is unaffected.
Red Hat Hardened Images:
-
Version 1.26.2-1.hum1 and below *
is unaffected.
Red Hat Lightspeed (formerly Insights) for Runtimes 1.0:
-
Version 1.0.2-1776288486 and below *
is unaffected.
Red Hat multicluster global hub 1.4.3:
-
Version 1779838819 and below *
is unaffected.
Red Hat OpenShift AI 2.25:
-
Version 1776773362 and below *
is unaffected.
Red Hat OpenShift Builds 1.7.1:
-
Version 1776846936 and below *
is unaffected.
Red Hat OpenShift Dev Spaces 3.27:
-
Version 1776789889 and below *
is unaffected.
Red Hat OpenShift distributed tracing 3.9.3:
-
Version 1776435680 and below *
is unaffected.
Red Hat OpenShift GitOps 1.18:
-
Version 1776755965 and below *
is unaffected.
Red Hat OpenShift GitOps 1.19:
-
Version 1776767162 and below *
is unaffected.
Red Hat OpenShift GitOps 1.2:
-
Version 1776773421 and below *
is unaffected.
Red Hat Quay 3.16:
-
Version 1779204086 and below *
is unaffected.
Red Hat Satellite 6.18:
-
Version 1778082595 and below *
is unaffected.
Red Hat Trusted Artifact Signer 1.3:
-
Version 1776339099 and below *
is unaffected.
Red Hat Web Terminal 1.11:
-
Version 1776966691 and below *
is unaffected.
Red Hat Web Terminal 1.12:
-
Version 1776959849 and below *
is unaffected.
Red Hat Web Terminal 1.13:
-
Version 1776197785 and below *
is unaffected.
Red Hat Web Terminal 1.14:
-
Version 1776199398 and below *
is unaffected.
Red Hat Web Terminal 1.15:
-
Version 1775672762 and below *
is unaffected.
Assisted Installer for Red Hat OpenShift Container Platform 2:
cert-manager Operator for Red Hat OpenShift:
Red Hat
Compliance Operator:
Red Hat
Confidential Compute Attestation:
Red Hat
Confidential Compute Attestation:
Red Hat
Cryostat 4:
Custom Metric Autoscaler operator for Red Hat Openshift:
Red Hat
Deployment Validation Operator:
Red Hat
ExternalDNS Operator:
Red Hat
ExternalDNS Operator:
External Secrets Operator for Red Hat OpenShift:
Red Hat
Fence Agents Remediation Operator:
Red Hat
File Integrity Operator:
Red Hat
Gatekeeper 3:
Logging Subsystem for Red Hat OpenShift:
Logging Subsystem for Red Hat OpenShift:
Red Hat
Logical Volume Manager Storage:
Red Hat
Logical Volume Manager Storage:
Red Hat
Logical Volume Manager Storage:
Red Hat
Machine Deletion Remediation Operator:
Red Hat
Migration Toolkit for Applications 8:
Red Hat
Migration Toolkit for Containers:
mirror registry for Red Hat OpenShift:
mirror registry for Red Hat OpenShift 2:
Red Hat
Multicluster Engine for Kubernetes:
Red Hat
Network Observability Operator:
Red Hat
Node HealthCheck Operator:
Red Hat
OpenShift Developer Tools and Services:
Red Hat
OpenShift Developer Tools and Services:
Red Hat
OpenShift Developer Tools and Services:
Red Hat
OpenShift Lightspeed:
Red Hat
OpenShift Pipelines:
Red Hat
OpenShift Serverless:
Red Hat
OpenShift Serverless:
Red Hat
OpenShift Serverless:
Red Hat
OpenShift Service Mesh 2:
Red Hat
OpenShift Service Mesh 2:
Red Hat
OpenShift Service Mesh 3:
Red Hat
OpenShift Service Mesh 3:
Power monitoring for Red Hat OpenShift:
Red Hat 3scale API Management Platform 2:
Red Hat 3scale API Management Platform 2:
Red Hat 3scale API Management Platform 2:
Red Hat 3scale API Management Platform 2:
Red Hat Advanced Cluster Security 4:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat build of Apache Camel - HawtIO 4:
Red Hat Certification Program for Red Hat Enterprise Linux 9:
Red Hat Connectivity Link 1:
Red Hat Developer Hub:
Red Hat Edge Manager 1:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 7:
Red Hat Enterprise Linux 7:
Red Hat Enterprise Linux 7:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux AI (RHEL AI) 3:
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift Cluster Manager CLI:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat Openshift Data Foundation 4:
Red Hat OpenShift for Windows Containers:
Red Hat OpenShift on AWS:
Red Hat OpenShift Virtualization 4:
Red Hat OpenShift Virtualization 4:
Red Hat OpenShift Virtualization 4:
Red Hat OpenShift Virtualization 4:
Red Hat OpenStack Platform 16.2:
Red Hat OpenStack Platform 16.2:
Red Hat OpenStack Platform 16.2:
Red Hat OpenStack Platform 17.1:
Red Hat OpenStack Platform 17.1:
Red Hat OpenStack Platform 17.1:
Red Hat OpenStack Platform 18.0:
Red Hat Quay 3:
Red Hat Quay 3:
Red Hat Satellite 6:
Red Hat Satellite 6:
Red Hat Service Interconnect 1:
Red Hat Service Interconnect 2:
Red Hat
Security Profiles Operator:
Red Hat
Service Telemetry Framework 1.5:
Red Hat
streams for Apache Kafka 3:
Red Hat
Zero Trust Workload Identity Manager:
Red Hat
Zero Trust Workload Identity Manager - Tech Preview:
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.