#VU119236 Improper certificate validation in Go programming language - CVE-2025-61727
Published: December 6, 2025 / Updated: February 17, 2026
Go programming language
Description
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists in crypto/x509 due to incorrect handling of wildcard SANs in the leaf certificate when processing excluded constraint in a certificate chain. A remote attacker can create a specially crafted certificate and bypass implemented domain restrictions and perform MitM or phishing attacks.