CVE-2026-32280Disclosure(golang / go)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 3 mentions (2026-04-08); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
go

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-04-08: 3Mentions · 2026-04-15: 1Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-06-26: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-15: 104-0804-1504-1704-1806-26
Signal classification3 categories
Disclosure
342.9%
General
342.9%
Patch
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-083
Disclosure2General1
2026-04-151
Disclosure1
2026-04-171
General1
2026-04-181
General1
2026-06-261
Patch1
Full discourse7 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🔒 ELSA-2026-29702: Atualização IMPORTANTE do runc no Oracle Linux 9 corrige 3 CVEs (CVE-2026-25679, CVE-2026-32280, CVE-2026-32281). Saiba mais: -> http://tinyurl.com/ub67wkx3 #Oracle https://t.co/WLfmq1SbNR

    Post summary

    Oracle Linux 9’s runc update (ESLA‑2026‑29702) addresses CVE‑2026‑25679, CVE‑2026‑32280 and CVE‑2026‑32281, with a link to additional details.

    1001086
    1.5K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2026-32280 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/457 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    Lambda Watchdog reports that CVE-2026-32280 is no longer present in the latest AWS Lambda base images, with no further exploitation or patch details provided.

    0000040
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2026-32280 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/457 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    Lambda Watchdog reported that CVE‑2026‑32280 is no longer found in the latest AWS Lambda base image scans, as noted in GitHub issue 457.

    0000018
    34 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 OpenTofu, Denial of Service, #CVE-2026-32280, #CVE-2026-32281, #CVE-2026-32283, #CVE-2026-32288 (Medium) https://dailycve.com/opentofu-denial-of-service-cve-2026-32280-cve-2026-32281-cve-2026-32283-cve-2026-32288-medium/

    Post summary

    The post announces medium‑severity Denial of Service vulnerabilities in OpenTofu, listing four CVEs but providing no details on PoCs, exploits, or mitigations.

    0000015
    181 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2026-32280 impacts stdlib in 26 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/457 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    The post announces that a previously unknown CVE (CVE‑2026‑32280) has been detected in AWS Lambda base images, but it offers no further exploitation, patch, or technical details.

    0000041
    31 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-32280 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-32280 #CVE-2026-32280 #CVE #CyberSecurity #InfoSec https://t.co/OjH1wVpfs3

    Post summary

    The post simply announces the existence of CVE‑2026‑32280 with minimal details and no supporting evidence or mitigations.

    0000039
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32280 During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermedi… https://www.cve.org/CVERecord?id=CVE-2026-32280

    Post summary

    The post references CVE-2026-32280 and gives a brief technical description of an issue in certificate chain building that could lead to excessive processing, but offers no proof‑of‑concept, exploit code, or patch details.

    0000072
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---

Explore more