CVE-2026-33810Disclosure(golang / go)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-295CWE-1289

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 4 mentions (2026-04-08); latest day: 1
  • 9 total mentions across 6 days

Affected systems

Vendors
Products
go

Deep dive

Activity timeline9 mentions / 6d
01234Mentions · 2026-04-08: 4Mentions · 2026-04-09: 1Mentions · 2026-04-15: 1Mentions · 2026-04-18: 1Mentions · 2026-04-20: 1Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-18: 1Patch / Workaround · 2026-04-20: 1Technical Details · 2026-04-08: 2Technical Details · 2026-04-15: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-28: 104-0804-0904-1504-1804-2004-28
Signal classification3 categories
Disclosure
555.6%
General
222.2%
Patch
222.2%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-084
Disclosure3General1
2026-04-091
General1
2026-04-151
Disclosure1
2026-04-181
Patch1
2026-04-201
Patch1
2026-04-281
Disclosure1
Full discourse9 posts
  • GMO Flatt Security株式会社@flatt_security
    Patch

    弊社エンジニアの報告した脆弱性が4件公開されました。アドバイザリを参照し最新版へのアップデート等の対策を行ってください。 セキュリティエンジニア @koketiki 報告 ① CVE-2026-39410(HonoにおけるCookie Prefix保護のバイパス) https://flatt.tech/cve/CVE-2026-39410 セキュリティエンジニア @k1rnt 報告 ② CVE-2026-33810(Goのcrypto/x509におけるDNS名制約検証の大文字・小文字不一致によるバイパス) https://flatt.tech/cve/CVE-2026-33810 コーポレートエンジニア @hamayanhamayan 報告 ③ CVE-2026-3429(Keycloakにおけるアクセス制御不備) https://flatt.tech/cve/CVE-2026-3429 ④ CVE-2026-28871(WebKitにおけるXSSに繋がりうるロジックの脆弱性) https://flatt.tech/cve/CVE-2026-28871

    Post summary

    The tweet lists four newly released CVEs, provides links to detailed advisory pages, and urges users to apply updates or other mitigations.

    08436810.8K
    5.6K followersView on X
  • てぃー@k1rnt
    General

    CVE++ した https://www.cve.org/CVERecord?id=CVE-2026-33810 https://pkg.go.dev/vuln/GO-2026-4866

    Post summary

    The content simply lists two CVE references via URLs, providing no further detail or actionable information about the vulnerabilities.

    0101401.0K
    666 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33810 When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case th… https://www.cve.org/CVERecord?id=CVE-2026-33810

    Post summary

    The post offers a concise description of the certificate chain validation issue (CVE‑2026‑33810) but provides no PoC, exploit details, active exploitation evidence, or patch information.

    00010117
    57.0K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Disclosure

    🚨 HIGH SEVERITY: CVE-2026-33810 (CVSS 8.2) Certificate validation flaw affects wildcard DNS SANs with excluded constraints. Impacts trusted certificate chain verification. CWE-295: Improper Certificate Validation #CVE #Vulnerability #PatchNow https://t.co/SlmTu6bLbj

    Post summary

    A new high‑severity certificate validation flaw (CVE‑2026‑33810) affecting wildcard DNS SANs has been disclosed; no PoC or exploitation evidence is mentioned, but the technical details and CVSS score are provided.

    0000047
    27 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-33810 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/463 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS Lambda base images have been updated to remove CVE‑2026‑33810, indicating the vulnerability is now patched.

    0000050
    31 followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🪟 CVE-2026-33810: another x509 “small” bug that lets attackers sidestep cert rules. PKI admins: congrats, your trust model has a loophole. Patch it yesterday. https://windowsforum.com/threads/cve-2026-33810-go-crypto-x509-excludedsubtrees-name-constraint-bypass-risk.413484/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #CertificateValidation #PkiSecurity #GoCryptoX509 #Cve2026

    Post summary

    An x509 certificate validation bug (CVE‑2026‑33810) that allows bypassing name‑constraint checks was disclosed and admins are urged to apply a patch immediately.

    0000031
    1.1K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2026-33810 impacts stdlib in 26 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/463 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new, unknown CVE (CVE-2026-33810) has been detected in AWS Lambda’s standard library images, with no available exploitation, patch, or detailed technical information disclosed yet.

    0000054
    31 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33810 Case-Sensitive DNS Constraint Bypass in Wildcard Certificate Validation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33810

    Post summary

    The message only references CVE-2026-33810 with a title indicating a DNS constraint bypass, providing no actionable details or evidence of exploitation.

    0000084
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-33810 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33810 #CVE-2026-33810 #CVE #CyberSecurity #InfoSec https://t.co/JKjc34y6Df

    Post summary

    The tweet merely announces the existence of CVE-2026-33810 without providing technical details, exploitation information, or remedial guidance.

    0000043
    123 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---

Explore more