Wildcard SAN Abuse in Go Certificate Chains
CVE-2025-61727
6.5MEDIUM
What is CVE-2025-61727?
The vulnerability arises from an improperly enforced subdomain constraint in the certificate chain, allowing the use of wildcard Subject Alternative Names (SANs) in leaf certificates. Specifically, constraints intended to exclude certain subdomains, such as test.example.com, fail to prevent certificates from using wildcard SANs like *.example.com. This oversight can potentially lead to unauthorized access or spoofing, as attackers can exploit these wildcard certificates to impersonate legitimate domains, thereby compromising the integrity of secure communications.
Affected Version(s)
crypto/x509 0 < 1.24.11
crypto/x509 1.25.0 < 1.25.5
