A denial-of-service vulnerability tracked as CVE-2026-32280 was disclosed in Go's standard library, affecting crypto/x509 and crypto/tls during X.509 certificate verification. The flaw stems from excessive certificate chain-building work in Verify when an attacker supplies a large number of candidate intermediate certificates, causing uncontrolled CPU and resource consumption and potentially making applications unavailable.
The issue affects systems that use Go to process untrusted TLS certificates or X.509 chains, particularly network-facing services that accept attacker-controlled certificate inputs. Red Hat rated the vulnerability Important with a CVSS v3.1 score of 7.5, mapped it to CWE-770, and published fixes across multiple products, including Red Hat Enterprise Linux 10 golang and several Ansible Automation Platform, Cryostat, and HawtIO components.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat listed Cryostat 4 on RHEL 9, component cryostat/cryostat-storage-rhel9, as fixed for CVE-2026-32280 in advisory RHSA-2026:14391.
Red Hat listed Red Hat Enterprise Linux 10 golang as fixed for CVE-2026-32280 in advisory RHSA-2026:10217.
Red Hat published its CVE record for CVE-2026-32280, describing an Important denial-of-service flaw in Go's crypto/x509 and crypto/tls packages caused by excessive intermediate certificate processing during chain building.
A Go issue was opened to track excessive certificate chain-building work in crypto/x509 Verify when many candidate parent certificates are supplied, associated with CVE-2026-32280.
Red Hat last modified its CVE-2026-32280 entry, updating the vendor record for the Go denial-of-service vulnerability.
Red Hat listed HawtIO 4.4.0 component hawtio-operator-container as fixed for CVE-2026-32280 in advisory RHSA-2026:25089.
Red Hat listed multiple Red Hat Ansible Automation Platform 2.5 and 2.6 components on RHEL 8, 9, and 10 as fixed for CVE-2026-32280 in advisories RHSA-2026:24761 and RHSA-2026:24762.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.