Wildcard SAN Abuse in Go Certificate Chains
CVE-2025-61727
What is CVE-2025-61727?
The vulnerability arises from an improperly enforced subdomain constraint in the certificate chain, allowing the use of wildcard Subject Alternative Names (SANs) in leaf certificates. Specifically, constraints intended to exclude certain subdomains, such as test.example.com, fail to prevent certificates from using wildcard SANs like *.example.com. This oversight can potentially lead to unauthorized access or spoofing, as attackers can exploit these wildcard certificates to impersonate legitimate domains, thereby compromising the integrity of secure communications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
crypto/x509 0 < 1.24.11
crypto/x509 1.25.0 < 1.25.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
