Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

Mozilla Firefox: Certificate email address constraints not properly enforced

CVE-2026-27137 BIT-golang-2026-27137
Summary

Mozilla Firefox may incorrectly verify invalid email addresses on secure websites. This can happen when a certificate includes multiple email address constraints with the same local part but different domain parts. To stay safe, update to the latest version of Mozilla Firefox.

What to do
  • Update stdlib to version 1.26.1.
  • Update golang to version 1.26.1.
Affected software
VendorProductAffected versionsFix available
stdlib > 1.26.0-0 , <= 1.26.1 1.26.1
golang > 1.26.0-0 , <= 1.26.1 1.26.1
Original title
When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will...
Original description
When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.
Published: 6 Mar 2026 · Updated: 13 Mar 2026 · First seen: 7 Mar 2026