CVE-2026-27137Patch(golang / go)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-03-06); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
go

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-03-06: 2Mentions · 2026-03-07: 2Mentions · 2026-03-08: 1Mentions · 2026-03-09: 1Mentions · 2026-03-16: 1Patch / Workaround · 2026-03-06: 2Patch / Workaround · 2026-03-09: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 2Technical Details · 2026-03-09: 1Technical Details · 2026-03-16: 103-0603-0703-0803-0903-16
Signal classification3 categories
Patch
342.9%
Disclosure
342.9%
General
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-062
Patch2
2026-03-072
Disclosure2
2026-03-081
General1
2026-03-091
Patch1
2026-03-161
Disclosure1
Full discourse7 posts
  • Go@golang
    Patch

    🌟 Go 1.26.1 and 1.25.8 are released! 🔐 Security: Includes security fixes for the standard library (CVE-2026-25679, CVE-2026-27137, CVE-2026-27138, CVE-2026-27139, CVE-2026-27142). 🗣 Announcement: https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk/m/41DopX_WAAAJ ⬇️ Download: https://go.dev/dl/#go1.26.1 #golang https://t.co/20adn9vysT

    Post summary

    Go 1.26.1 and 1.25.8 release notes announce security fixes for several CVEs, with no PoC, exploit, or active exploitation references given.

    511196015260.9K
    207.1K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    5 CVEs fixed in Go 1.26.1, 1.25.8 https://www.openwall.com/lists/oss-security/2026/03/06/1 CVE-2026-27137: crypto/x509: incorrect enforcement of email constraints CVE-2026-27138: crypto/x509: panic in name constraint checking for malformed certificates +next tweet

    Post summary

    Announcement of Go 1.26.1 and 1.25.8 releases that fix five CVEs, specifically CVE-2026-27137 and CVE-2026-27138, with brief technical descriptions.

    10031280
    4.4K followersView on X
  • Doctor Kloud@doctorkloud
    Disclosure

    La validation des contraintes email dans crypto/x509 est défaillante. Un attaquant peut forger un certificat accepté comme légitime. Vérifiez vos chaînes de confiance. Les PKI internes sont exposées. #CVE-2026-27137 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27137

    Post summary

    The post highlights a flaw in email constraint validation within crypto/x509 that permits attackers to forge legitimate certificates, exposing internal PKIs, but does not provide PoC, exploit tools, or evidence of active exploitation.

    0000040
    13 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2026-27137 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/436 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The tweet reports that CVE-2026-27137 is no longer found in the latest AWS Lambda base image scans, implying it may have been patched or removed, but no further technical or exploit details are provided.

    0000043
    31 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27137 When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain p… https://www.cve.org/CVERecord?id=CVE-2026-27137

    Post summary

    The snippet references CVE-2026-27137 and provides a brief technical description of the issue with certificate email constraints, linking to the CVE record. No PoC, exploit, patch, or active exploitation details are included.

    0000093
    56.6K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2026-27137 impacts stdlib in 27 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/436 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new CVE (CVE‑2026‑27137) affecting AWS Lambda's stdlib in 27 base images is announced, with links to issue discussion, but no PoC, exploit, or mitigation details are provided.

    0000041
    31 followersView on X
  • Jeremie@JPC_WebTahiti
    Patch

    CVE-2026-27137 is probably the most notable security fix in Go 1.26.1. It affects certificate verification in crypto/x509

    Post summary

    CVE-2026-27137 is a critical bug affecting certificate verification in Go's crypto/x509 package, fixed by the release of version 1.26.1.

    00000154
    117 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo1.26.0--

Explore more