A denial-of-service vulnerability tracked as CVE-2026-32281 was disclosed in Go’s crypto/x509 package after maintainers found certificate policy validation can degrade to quadratic work when processing chains with very large PolicyMappings. The flaw affects verification of otherwise trusted certificate chains anchored in VerifyOptions.Roots or the system certificate pool, allowing excessive CPU and resource consumption during chain validation. Exploitation requires a specially crafted chain tied to a compromised trusted root, but Red Hat still rated the issue Moderate while noting higher severity scores were assigned by other scoring authorities.
Red Hat said fixes were issued across a wide range of products, including multiple Red Hat Enterprise Linux versions and update streams, Satellite, Cryostat, OpenStack, Ansible Automation Platform, and RHEM/flightctl, with additional affected products added as availability changed after initial triage. Red Hat also stated there is no acceptable mitigation short of applying vendor updates, making patch deployment the primary response for organizations running Go-based services or platforms that rely on crypto/x509 certificate chain validation.

See affected versions and whether adversaries are exploiting it.
17 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Important-severity advisory RHSA-2026:61906 for the runc package on Red Hat Enterprise Linux 9, including EUS 9.6. The update remediates the Go certificate-chain denial-of-service vulnerabilities CVE-2026-32280 and CVE-2026-32281.
Red Hat published advisory RHSA-2026:47716 for grafana-pcp on RHEL 9.4 channels, delivering version 5.1.1-8.el9_4 rebuilt with golang 1.25.9. The update addresses CVE-2026-32281 along with four other Go-related vulnerabilities.
Red Hat published advisory RHSA-2026:29195 for buildah on Red Hat Enterprise Linux 10, releasing buildah 1.43.1-2.el10_2. The update fixes CVE-2026-32281 along with three other Go vulnerabilities across multiple RHEL 10 architectures and support channels.
Red Hat listed Cryostat 4 on RHEL 9 components cryostat-rhel9-operator and cryostat-storage-rhel9 as fixed in RHSA-2026:28010. The fix date is explicitly stated as June 22, 2026.
Red Hat published advisory RHSA-2026:23103 for delve on Red Hat Enterprise Linux 10.0 Extended Update Support and 4-year support/update channels. The 2026-06-04 update released delve 1.25.2-4.el10_0 and fixed CVE-2026-32281 along with CVE-2026-32280 and CVE-2026-32283.
Red Hat published advisory RHSA-2026:23102 for delve on Red Hat Enterprise Linux 10, releasing delve 1.26.1-2.el10_2. The update fixes CVE-2026-32281 along with CVE-2026-32280 and CVE-2026-32283 across multiple RHEL 10 architectures and support variants.
Red Hat published advisory RHSA-2026:22309 for the rhc package on Red Hat Enterprise Linux 9, releasing rhc 0.2.7-7.el9_8 across multiple architectures and support channels. The 2026-06-01 update fixes CVE-2026-32281 along with CVE-2026-32280.
Red Hat published advisory RHSA-2026:20571 for skopeo on Red Hat Enterprise Linux 10.0 Extended Update Support and related 4-year support/update channels. The 2026-05-26 update released skopeo 1.18.1-3.el10_0.2 and fixed CVE-2026-32281 along with CVE-2026-32280 and CVE-2026-32283.
Red Hat published advisory RHSA-2026:20570 for podman on Red Hat Enterprise Linux 10.0 Extended Update Support and related 10.0 channels. The 2026-05-26 update released podman 5.4.0-15.el10_0.2 and fixed CVE-2026-32281 along with CVE-2026-32280 and CVE-2026-32283.
Red Hat listed Red Hat Enterprise Linux 10 opentelemetry-collector as fixed for CVE-2026-32281 in advisory RHSA-2026:19135. The advisory date is explicitly given as May 19, 2026.
Red Hat's CVE record for CVE-2026-32281 was last modified on May 15, 2026. The record links the flaw to Bugzilla 2456333, the Go issue tracker entry, and related vulnerability tracking identifiers.
Red Hat listed Red Hat Enterprise Linux 10 golang as fixed for CVE-2026-32281 in advisory RHSA-2026:10217. This is one of the earliest explicit product fix dates provided in the references.
Red Hat states that CVE-2026-32281, a denial-of-service flaw in Go's crypto/x509 certificate chain validation, was made public on April 8, 2026. The issue involves inefficient processing of certificate chains with very large policy mappings.
Red Hat opened Bugzilla entry 2456339 to track CVE-2026-32280, a high-severity denial-of-service flaw in Go's crypto/x509 and crypto/tls certificate chain building. The bug was reported by OSIDB Bzimport and remained in NEW status in the referenced entry.
Red Hat listed Ansible Automation Platform 2.6 for RHEL 9 and RHEL 10 components, including receptor and automation-gateway-proxy, as fixed in RHSA-2026:42079. The references explicitly date these fixes to July 20, 2026.
Red Hat listed Ansible Automation Platform 2.5 for RHEL 8 and RHEL 9 receptor components as fixed in RHSA-2026:42078. The references explicitly date these fixes to July 20, 2026.
Mirco Geremia stated that rhem-1.1/flightctl was added as an affected and tracked product because it went generally available after initial triage but remained vulnerable. This expanded the set of Red Hat products tracked for CVE-2026-32281.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
13 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcego.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.