CVE-2026-27137: Incorrect enforcement of email constraints in crypto/x509
Published Mar 6, 2026
·Updated
Incorrect enforcement of email constraints in crypto/x509
Other sources
When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.
— MITRE
Affected Software
5 affected componentsFixes available
Microsoft azl3 golang 1.26.0-1
Microsoft azl3 golang 1.25.7-1
Golang Go=1.26.0
Microsoft azl3 golang 1.26.0-1<1.26.1-1
1.26.1-1
Microsoft azl3 golang 1.25.7-1<1.25.8-1
1.25.8-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.26.1-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.25.8-1
Event History
Mar 6, 2026
CVE Published
via MITRE·09:28 PM
Data Sourced
via MITRE·09:28 PM
DescriptionWeakness
Data Sourced
via Red Hat·10:02 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Mar 11, 2026
Data Sourced
via Microsoft·08:03 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:03 AM
Affected Software
Updated
via Microsoft·08:03 AM
DescriptionSeverityWeakness
Updated
via Microsoft·08:03 AM
WeaknessAffected Software