Go disclosed CVE-2026-33810, a certificate validation flaw in crypto/x509 in Go 1.26 that can cause excluded DNS name constraints to be enforced incorrectly for wildcard Subject Alternative Names. The bug appears when a wildcard SAN such as *.example.com is evaluated against an excluded constraint written with different letter casing, such as EXAMPLE.COM, allowing the wildcard domain to bypass the exclusion during certificate chain verification.
The issue affects otherwise trusted certificate chains anchored in VerifyOptions.Roots or the system certificate pool, narrowing exposure to chains that already terminate at a trusted root CA. Go tracked the bug as issue #78332, credited the report to Riyas from Saintgits College of Engineering, k1rnt, and @1seal, and later published a fix on the release-branch.go1.26; downstream vendors including SUSE also opened advisories for the vulnerability.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
SUSE tracked CVE-2026-33810 in bug 1261662, identifying it as a Go 1.26 crypto/x509 vulnerability involving excluded DNS constraints on wildcard domains. The entry reflects downstream vendor tracking of the disclosed flaw.
A commit on the Go 1.26 release branch addressed the crypto/x509 wildcard constraint map case-handling issue tied to CVE-2026-33810. This represents the code fix for the certificate validation flaw.
Go disclosed CVE-2026-33810 as a certificate validation flaw in Go 1.26's crypto/x509 package. The bug allows excluded DNS constraints to be applied incorrectly to wildcard DNS SANs when letter casing differs, potentially bypassing constraints for otherwise trusted chains.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
bugzilla.suse.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcego.dev
Open sourcedeb.freexian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.