CVE-2026-33810 is a certificate validation bypass vulnerability that affects DNS constraint verification in certificate chains. The flaw occurs when wildcard DNS Subject Alternative Names (SANs) use different character cases than the excluded DNS constraints, causing the constraints to be incorrectly bypassed during verification. This issue only affects validation of trusted certificate chains issued by root CAs within the VerifyOptions.Roots CertPool or system certificate pool. The vulnerability carries a HIGH severity rating with a CVSS score of 8.2, reflecting its network-accessible attack vector, low complexity, and lack of required privileges or user interaction. The impact includes high confidentiality risk and limited integrity compromise, though availability is not affected. This indicates a practical exploitation scenario for certificate-based security mechanisms. There is currently no evidence of active exploitation, as the vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat tracking lists. The EPSS score of 0.0001 indicates very low probability of exploitation in the wild relative to other vulnerabilities. However, the moderate FAUCET Risk Score of 50.0 suggests organizations should still prioritize patching, particularly those relying on certificate-based authentication controls.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.26.0, < 1.26.2CPE matchmatch criteria | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.