CVE-2017-1000097: High severity Golang Go vulnerability
Published Oct 4, 2017
·Updated
On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.
Affected Software
2 affected components
Golang Go<1.6.4
Golang Go>=1.7<1.7.4
Event History
Oct 4, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Sep 4, 2025
Data Sourced
via Microsoft·04:38 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1000097?
CVE-2017-1000097 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2017-1000097?
To fix CVE-2017-1000097, upgrade to Go version 1.7.4 or later.
3
What systems are affected by CVE-2017-1000097?
CVE-2017-1000097 affects Go versions prior to 1.7.4 on Darwin systems.
4
What is the impact of CVE-2017-1000097?
The impact of CVE-2017-1000097 allows a Go program to validate a connection using a root certificate that the user has explicitly not trusted.
5
Who is impacted by CVE-2017-1000097?
Users of the Go programming language on Darwin who utilize root certificates in their Keychain are impacted by CVE-2017-1000097.