CVE-2026-27138Patch(golang / go)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the chain has excluded name constraints. This can crash programs that are either directly verifying X.509 certificate chains, or those that use TLS.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-07); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
go

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-06: 1Mentions · 2026-03-07: 2Mentions · 2026-03-08: 1Mentions · 2026-03-09: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-03-07: 2Technical Details · 2026-03-09: 103-0603-0703-0803-09
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-061
Patch1
2026-03-072
Disclosure2
2026-03-081
Patch1
2026-03-091
Patch1
Full discourse5 posts
  • Go@golang
    Patch

    🌟 Go 1.26.1 and 1.25.8 are released! 🔐 Security: Includes security fixes for the standard library (CVE-2026-25679, CVE-2026-27137, CVE-2026-27138, CVE-2026-27139, CVE-2026-27142). 🗣 Announcement: https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk/m/41DopX_WAAAJ ⬇️ Download: https://go.dev/dl/#go1.26.1 #golang https://t.co/20adn9vysT

    Post summary

    The tweet announces the release of Go 1.26.1 and 1.25.8, noting that they include security fixes for several standard-library CVEs, and provides links to the announcement and download.

    511196015260.9K
    207.1K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    5 CVEs fixed in Go 1.26.1, 1.25.8 https://www.openwall.com/lists/oss-security/2026/03/06/1 CVE-2026-27137: crypto/x509: incorrect enforcement of email constraints CVE-2026-27138: crypto/x509: panic in name constraint checking for malformed certificates +next tweet

    Post summary

    The tweet announces that five CVEs, including two affecting Go’s crypto/x509, have been fixed in the latest Go releases, but it does not mention any PoC, exploit, or active exploitation.

    10031280
    4.4K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-27138 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/437 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    Lambda Watchdog reports that CVE‑2026‑27138 is no longer found in the latest AWS Lambda base images, implying the vulnerability has been removed or patched in those images.

    0000043
    31 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27138 Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the chain has excluded name constraints. This can … https://www.cve.org/CVERecord?id=CVE-2026-27138

    Post summary

    The text discloses CVE‑2026‑27138, describing a certificate verification panic triggered by the presence of an empty DNS name and excluded name constraints in the chain.

    0000086
    56.6K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2026-27138 impacts stdlib in 27 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/437 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    The tweet reports a new CVE-2026-27138 affecting stdlib in AWS Lambda base images, but offers no exploit code, patches, or evidence of active exploitation.

    0000038
    31 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo1.26.0--

Explore more