{"id":"CVE-2025-22874","title":"crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509 (CVE-2025-22874)","summary":"A flaw was found in Go's crypto/x509 package. This vulnerability allows improper certificate validation, bypassing policy constraints via using ExtKeyUsageAny in VerifyOptions.KeyUsages.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvssSource":"vendor","cwe":"CWE-295","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.20","affected":["assisted_installer_for_red_hat_openshift_container_platform 2","builds_for_red_hat_openshift","cert_manager_operator_for_red_hat_openshift","confidential_compute_attestation","deployment_validation_operator","external_secrets_operator_for_red_hat_openshift_tech_preview","openshift_lightspeed","openshift_serverless","enterprise_linux 10","enterprise_linux 8","enterprise_linux 9","openshift_ai_rhoai","openshift_dev_workspaces_operator","openshift_distributed_tracing 3","runtimes_inventory_operator","trusted_application_pipeline","trusted_artifact_signer","zero_trust_workload_identity_manager_tech_preview","enterprise_linux_appstream_v_10","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_v_9","builds_for_red_hat_openshift 1.5.2","lightspeed_formerly_insights_for_runtimes 1.0","openshift_container_platform 4.20","openshift_gitops 1.16","openshift_gitops 1.17","openshift_distributed_tracing 3.7.0","trusted_artifact_signer 1.2"],"patched":["enterprise_linux_appstream_v_10","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_v_9","builds_for_red_hat_openshift 1.5.2","lightspeed_formerly_insights_for_runtimes 1.0","openshift_container_platform 4.20","openshift_gitops 1.16","openshift_gitops 1.17","openshift_distributed_tracing 3.7.0","trusted_artifact_signer 1.2"],"published":"2025-06-11","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:01:21+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-22874.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-22874.json"},{"url":"https://access.redhat.com/security/cve/CVE-2025-22874"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2372320"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-22874"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-22874"},{"url":"https://go.dev/cl/670375"},{"url":"https://go.dev/issue/73612"},{"url":"https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A"},{"url":"https://pkg.go.dev/vuln/GO-2025-3749"},{"url":"https://access.redhat.com/errata/RHSA-2025:10677"},{"url":"https://access.redhat.com/errata/RHSA-2026:47719"},{"url":"https://access.redhat.com/errata/RHSA-2026:47712"},{"url":"https://access.redhat.com/errata/RHSA-2025:10676"},{"url":"https://access.redhat.com/errata/RHSA-2025:13931"},{"url":"https://access.redhat.com/errata/RHSA-2025:23236"},{"url":"https://access.redhat.com/errata/RHSA-2025:19003"},{"url":"https://access.redhat.com/errata/RHSA-2025:19890"},{"url":"https://access.redhat.com/errata/RHSA-2025:17730"},{"url":"https://access.redhat.com/errata/RHSA-2025:17731"},{"url":"https://access.redhat.com/errata/RHSA-2025:17043"},{"url":"https://access.redhat.com/errata/RHSA-2025:14470"},{"url":"https://access.redhat.com/errata/RHSA-2025:14473"},{"url":"https://access.redhat.com/errata/RHSA-2025:14472"},{"url":"https://access.redhat.com/errata/RHSA-2025:14476"},{"url":"https://access.redhat.com/errata/RHSA-2025:14484"},{"url":"https://access.redhat.com/errata/RHSA-2025:14479"},{"url":"https://access.redhat.com/errata/RHSA-2025:14481"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00374,"epssPercentile":0.31189,"aliases":["GO-2025-3749","BIT-golang-2025-22874"],"ecosystem":"go","ingestedAt":"2026-08-27T19:27:47.783Z","slug":"CVE-2025-22874","body":"## Overview\n\nA flaw was found in Go's crypto/x509 package. This vulnerability allows improper certificate validation, bypassing policy constraints via using ExtKeyUsageAny in VerifyOptions.KeyUsages.\n\n## Vendor advisories\n\n- **RHSA-2025:10677** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2025-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2025:10677)\n- **RHSA-2026:47719** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:47719)\n- **RHSA-2026:47712** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:47712)\n- **RHSA-2025:10676** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2025-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2025:10676)\n- **RHSA-2025:13931** · Red Hat · fixed in: Builds for Red Hat OpenShift 1.5.2 · released 2025-08-14 · [advisory](https://access.redhat.com/errata/RHSA-2025:13931)\n- **RHSA-2025:23236** · Red Hat · fixed in: Red Hat Lightspeed (formerly Insights) for Runtimes 1.0 · released 2025-12-16 · [advisory](https://access.redhat.com/errata/RHSA-2025:23236)\n- **RHSA-2025:19003** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.20 · released 2025-10-30 · [advisory](https://access.redhat.com/errata/RHSA-2025:19003)\n- **RHSA-2025:19890** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.20 · released 2025-11-11 · [advisory](https://access.redhat.com/errata/RHSA-2025:19890)\n- **RHSA-2025:17730** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.16 · released 2025-10-09 · [advisory](https://access.redhat.com/errata/RHSA-2025:17730)\n- **RHSA-2025:17731** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.17 · released 2025-10-09 · [advisory](https://access.redhat.com/errata/RHSA-2025:17731)\n- **RHSA-2025:17043** · Red Hat · fixed in: Red Hat OpenShift distributed tracing 3.7.0 · released 2025-09-30 · [advisory](https://access.redhat.com/errata/RHSA-2025:17043)\n- **Red Hat VEX** · Important · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, cert-manager Operator for Red Hat OpenShift, Confidential Compute Attestation, Deployment Validation Operator, external secrets operator for Red Hat OpenShift - Tech Preview, … · no fix planned: Builds for Red Hat OpenShift, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Runtimes Inventory Operator, … · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-22874.json)\n\n**crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509** — rated Important by Red Hat. Released 2025-06-11, updated 2026-09-10.\n\nAffected:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Builds for Red Hat OpenShift\n- cert-manager Operator for Red Hat OpenShift\n- Confidential Compute Attestation\n- Deployment Validation Operator\n- external secrets operator for Red Hat OpenShift - Tech Preview\n- OpenShift Lightspeed\n- OpenShift Serverless\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Dev Workspaces Operator\n- Red Hat OpenShift distributed tracing 3\n- Red Hat Runtimes Inventory Operator\n- Red Hat Trusted Application Pipeline\n- Red Hat Trusted Artifact Signer\n- Zero Trust Workload Identity Manager - Tech Preview\n\nFixed:\n\n- Red Hat Enterprise Linux AppStream (v. 10)\n- Red Hat Enterprise Linux AppStream E4S (v.9.2)\n- Red Hat Enterprise Linux AppStream E4S (v.9.4)\n- Red Hat Enterprise Linux AppStream (v. 9)\n- Builds for Red Hat OpenShift 1.5.2\n- Red Hat Lightspeed (formerly Insights) for Runtimes 1.0\n- Red Hat OpenShift Container Platform 4.20\n- Red Hat OpenShift GitOps 1.16\n- Red Hat OpenShift GitOps 1.17\n- Red Hat OpenShift distributed tracing 3.7.0\n- Red Hat Trusted Artifact Signer 1.2\n\nNo fix planned:\n\n- Builds for Red Hat OpenShift\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat Runtimes Inventory Operator\n- Zero Trust Workload Identity Manager - Tech Preview\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- cert-manager Operator for Red Hat OpenShift\n- Confidential Compute Attestation\n- Deployment Validation Operator\n- external secrets operator for Red Hat OpenShift - Tech Preview\n- OpenShift Lightspeed\n- OpenShift Serverless\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Dev Workspaces Operator\n- Red Hat OpenShift distributed tracing 3\n- Red Hat Trusted Application Pipeline\n- Red Hat Trusted Artifact Signer\n\nNot affected:\n\n- Builds for Red Hat OpenShift 1.5.2\n- Red Hat Lightspeed (formerly Insights) for Runtimes 1.0\n- Red Hat OpenShift Container Platform 4.20\n- Red Hat OpenShift GitOps 1.16\n- Red Hat OpenShift GitOps 1.17\n- Red Hat OpenShift distributed tracing 3.7.0\n- Red Hat Trusted Artifact Signer 1.2\n- Custom Metric Autoscaler operator for Red Hat Openshift\n- Multiarch Tuning Operator\n- NBDE Tang Server\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:10677\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:47719\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:47712\n\n## Package advisory (CVE-2025-22874)\n\nAffected packages:\n\n- `stdlib >= 1.24.0-0, < 1.24.4`\n\nPatched in:\n\n- `stdlib 1.24.4`\n\nSource: https://osv.dev/vulnerability/GO-2025-3749","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":4796,"id":"CVE-2025-22874","ts":1788887207121,"field":"cvss","old":null,"new":"7.5"},{"seq":4795,"id":"CVE-2025-22874","ts":1788887207121,"field":"severity","old":"none","new":"high"},{"seq":3679,"id":"CVE-2025-22874","ts":1788886324163,"field":"cvss","old":"7.5","new":null},{"seq":3678,"id":"CVE-2025-22874","ts":1788886324163,"field":"severity","old":"high","new":"none"},{"seq":3169,"id":"CVE-2025-22874","ts":1788883133185,"field":"cvss","old":null,"new":"7.5"},{"seq":3168,"id":"CVE-2025-22874","ts":1788883133185,"field":"severity","old":"none","new":"high"}]}