Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

Incorrect Email Address Constraints in Certificate Chain Can Cause Validation Failure

DEBIAN-CVE-2026-27137
Summary

A certificate chain with multiple email address constraints that share local but have different domain parts can cause incorrect validation. This can lead to security issues if not addressed. To resolve this, update your certificate handling process to correctly apply all email address constraints.

What to do
  • Update debian golang-1.26 to version 1.26.1-1.
Affected software
VendorProductAffected versionsFix available
debian golang-1.26 <= 1.26.1-1 1.26.1-1
Original title
When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will...
Original description
When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.
Published: 6 Mar 2026 · Updated: 13 Mar 2026 · First seen: 10 Mar 2026