CVE-2025-61727 - Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509
CVE ID : CVE-2025-61727
Published : Dec. 3, 2025, 8:16 p.m. | 57 minutes ago
Description : An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Dec. 3, 2025, 8:16 p.m. | 57 minutes ago
Description : An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...