CVE-2026-32281Disclosure(golang / go)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 4 classified signals
  • False Positive: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-04-08); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
go

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-04-08: 3Mentions · 2026-04-15: 1Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-06-26: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-15: 104-0804-1504-1704-1806-26
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
False Positive
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-083
Disclosure3
2026-04-151
Disclosure1
2026-04-171
Patch1
2026-04-181
False Positive1
2026-06-261
Patch1
Full discourse7 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🔒 ELSA-2026-29702: Atualização IMPORTANTE do runc no Oracle Linux 9 corrige 3 CVEs (CVE-2026-25679, CVE-2026-32280, CVE-2026-32281). Saiba mais: -> http://tinyurl.com/ub67wkx3 #Oracle https://t.co/WLfmq1SbNR

    Post summary

    The tweet announces a patch update for Oracle Linux 9 that addresses three CVEs; no exploit or vulnerability details are provided.

    1001086
    1.5K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    False Positive

    🔍 Lambda Watchdog detected that CVE-2026-32281 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/458 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS Lambda base images no longer contain CVE-2026-32281, with no evidence of PoC, exploit, or patch; the post functions as a debunking statement.

    0000039
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-32281 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/458 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    Lambda Watchdog reports that CVE-2026-32281 is no longer present in the newest AWS Lambda base images, indicating the vulnerability has been removed or mitigated by updates.

    0000019
    34 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 OpenTofu, Denial of Service, #CVE-2026-32280, #CVE-2026-32281, #CVE-2026-32283, #CVE-2026-32288 (Medium) https://dailycve.com/opentofu-denial-of-service-cve-2026-32280-cve-2026-32281-cve-2026-32283-cve-2026-32288-medium/

    Post summary

    The tweet announces several medium‑severity Denial‑of‑Service CVEs for OpenTofu, linking to a DailyCVE article, but offers no PoC, exploit code, patches, or evidence of active exploitation.

    0000015
    181 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2026-32281 impacts stdlib in 26 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/458 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new CVE (CVE-2026-32281) has been identified affecting the standard library in 26 AWS Lambda base images, with links to an issue discussion but no evidence of exploitation or PoC.

    0000041
    31 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-32281 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-32281 #CVE-2026-32281 #CVE #CyberSecurity #InfoSec https://t.co/FATjej3oSN

    Post summary

    A new CVE (CVE‑2026‑32281) has been announced with no substantive details; the post functions as a notice of the vulnerability's existence.

    0000036
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32281 Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly c… https://www.cve.org/CVERecord?id=CVE-2026-32281

    Post summary

    The text refers to CVE‑2026‑32281, describing an unexpected inefficiency in certificate chain validation with many policy mappings, but provides no evidence of exploitation, patches, or proof‑of‑concepts.

    00000122
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---

Explore more