An Important vulnerability tracked as CVE-2026-33810 affects Go's crypto/x509 package and can allow a certificate validation bypass during trusted certificate chain verification. The flaw stems from excluded DNS constraints not being correctly applied to wildcard DNS Subject Alternative Names when the SAN's case differs from the constraint, creating a path for a malicious certificate to be accepted when it should be rejected.
Red Hat assigned the issue a CVSS v3 score of 8.8 and warned that affected products could accept malicious certificates from otherwise trusted chains, weakening the certificate trust model. Red Hat said multiple affected products and components have been fixed through security errata, while the CVE record formally tracks the issue as CVE-2026-33810.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat listed Cryostat 4 on RHEL 9, component cryostat/cryostat-storage-rhel9, as fixed for CVE-2026-33810 in advisory RHSA-2026:14391.
Red Hat published CVE-2026-33810, describing an Important vulnerability in Go's crypto/x509 package that can allow certificate validation bypass during trusted certificate chain verification. Red Hat assigned the issue a CVSS v3 score of 8.8.
Red Hat listed Red Hat Enterprise Linux 10 component yggdrasil as fixed for CVE-2026-33810 in advisory RHSA-2026:57126.
Red Hat listed fixes for CVE-2026-33810 in Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and 8.6 Extended Update Support Long-Life Add-On for component container-tools:rhel8 in advisory RHSA-2026:51288.
Red Hat listed HawtIO 4.4.0, component hawtio-operator-container, as fixed for CVE-2026-33810 in advisory RHSA-2026:25089.
Red Hat listed Red Hat Enterprise Linux 9.4 Extended Update Support component opentelemetry-collector as fixed for CVE-2026-33810 in advisory RHSA-2026:19721.
Red Hat listed Red Hat Enterprise Linux 10.0 Extended Update Support component opentelemetry-collector as fixed for CVE-2026-33810 in advisory RHSA-2026:19719.
Red Hat listed Red Hat Enterprise Linux 9 component opentelemetry-collector as fixed for CVE-2026-33810 in advisory RHSA-2026:19353.
Red Hat listed fixes for CVE-2026-33810 in Red Hat Enterprise Linux 10 for components opentelemetry-collector and golang-github-openprinting-ipp-usb via advisories RHSA-2026:19135 and RHSA-2026:19144.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.