{"id":"CVE-2026-32281","title":"crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)","summary":"A flaw was found in Go's `crypto/x509` package. A remote attacker could exploit this by presenting a specially crafted certificate chain containing a large number of policy mappings. This inefficient validation process consumes excessive r…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-1050","vendor":"Red Hat","product":"Red Hat Enterprise Linux AppStream EUS (v.9.6)","affected":["assisted_installer_for_red_hat_openshift_container_platform 2","cert_manager_operator_for_red_hat_openshift","confidential_compute_attestation","deployment_validation_operator","external_secrets_operator_for_red_hat_openshift","externaldns_operator","fence_agents_remediation_operator","gatekeeper 3","logging_subsystem_for_red_hat_openshift","machine_deletion_remediation_operator","migration_toolkit_for_applications 8","multiarch_tuning_operator","multicluster_engine_for_kubernetes","multicluster_global_hub","node_healthcheck_operator","openshift_developer_tools_and_services","openshift_pipelines","openshift_serverless","openshift_service_mesh 3","power_monitoring_for_red_hat_openshift","3scale_api_management_platform 2","advanced_cluster_management_for_kubernetes 2","advanced_cluster_security 4","amq_broker 7","ansible_automation_platform 2","build_of_apache_camel_hawtio 4","build_of_apicurio_registry 2","certification_program_for_red_hat_enterprise_linux 9","connectivity_link 1","enterprise_linux 10","enterprise_linux 8","enterprise_linux 9","jboss_web_server 6","openshift_ai_rhoai","openshift_cluster_manager_cli","openshift_container_platform 4","openshift_data_foundation 4","openshift_dev_spaces","openshift_for_windows_containers","openshift_on_aws"],"patched":["ansible_automation_platform_2_6_for_rhel 10","rhem_1_1_for_rhel 10","enterprise_linux_server_v_7_els","ansible_automation_platform_2_5_for_rhel 8","openstack_platform 16.2","satellite_6_16_for_rhel 8","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","cryostat_4_on_rhel 9","rhem_1_0_for_rhel 9","rhem_1_1_for_rhel 9","openstack_services_on_openshift 18.0","9base_rhoso_tools_18","satellite_6_16_for_rhel 9","satellite_6_19_for_rhel 9","enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_aus_v_8_6","enterprise_linux_appstream_eus_extension_v_8_6","enterprise_linux_appstream_e4s_v_8_8","enterprise_linux_appstream_tus_v_8_8","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_eus_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","enterprise_linux_codeready_linux_builder_eus_v_10_0","enterprise_linux_codeready_linux_builder_v_10","codeready_linux_builder_eus_v_9_6","enterprise_linux_codeready_linux_builder_v_9","cluster_observability_operator 1.5.0","custom_metric_autoscaler 2.19","devworkspace_operator 0.42","hawtio_hawtio 4.4.0","logging_subsystem_for_red_hat_openshift 6.2","logging_subsystem_for_red_hat_openshift 6.4","logging_subsystem_for_red_hat_openshift 6.5","logging_for_red_hat_openshift 6","multicluster_global_hub 1.4.9"],"published":"2026-04-08","updated":"2026-09-21","sourceUpdated":"2026-09-21T16:49:02+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32281.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32281.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-32281"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2456333"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-32281"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32281"},{"url":"https://go.dev/cl/758061"},{"url":"https://go.dev/issue/78281"},{"url":"https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"},{"url":"https://pkg.go.dev/vuln/GO-2026-4946"},{"url":"https://access.redhat.com/errata/RHSA-2026:42079"},{"url":"https://access.redhat.com/errata/RHSA-2026:41019"},{"url":"https://access.redhat.com/errata/RHSA-2026:16101"},{"url":"https://access.redhat.com/errata/RHSA-2026:42078"},{"url":"https://access.redhat.com/errata/RHSA-2026:54757"},{"url":"https://access.redhat.com/errata/RHSA-2026:27076"},{"url":"https://access.redhat.com/errata/RHSA-2026:28010"},{"url":"https://access.redhat.com/errata/RHSA-2026:36796"},{"url":"https://access.redhat.com/errata/RHSA-2026:39810"},{"url":"https://access.redhat.com/errata/RHSA-2026:34365"},{"url":"https://access.redhat.com/errata/RHSA-2026:20569"},{"url":"https://access.redhat.com/errata/RHSA-2026:23103"},{"url":"https://access.redhat.com/errata/RHSA-2026:67149"},{"url":"https://access.redhat.com/errata/RHSA-2026:16024"},{"url":"https://access.redhat.com/errata/RHSA-2026:18032"},{"url":"https://access.redhat.com/errata/RHSA-2026:18027"},{"url":"https://access.redhat.com/errata/RHSA-2026:19719"},{"url":"https://access.redhat.com/errata/RHSA-2026:27711"},{"url":"https://access.redhat.com/errata/RHSA-2026:20570"},{"url":"https://access.redhat.com/errata/RHSA-2026:22713"},{"url":"https://access.redhat.com/errata/RHSA-2026:20571"},{"url":"https://access.redhat.com/errata/RHSA-2026:19450"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00355,"epssPercentile":0.29219,"aliases":["GO-2026-4946","BIT-golang-2026-32281"],"ecosystem":"go","ingestedAt":"2026-07-09T18:56:37.030Z","slug":"CVE-2026-32281","body":"## Overview\n\nA flaw was found in Go's `crypto/x509` package. A remote attacker could exploit this by presenting a specially crafted certificate chain containing a large number of policy mappings. This inefficient validation process consumes excessive resources, which can lead to a denial of service (DoS) for applications or systems performing certificate validation.\n\n## Vendor advisories\n\n- **RHSA-2026:42079** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 10, Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42079)\n- **RHSA-2026:41019** · Red Hat · fixed in: RHEM 1.1 for RHEL 10, RHEM 1.1 for RHEL 9 · released 2026-07-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:41019)\n- **RHSA-2026:16101** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS) · released 2026-05-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:16101)\n- **RHSA-2026:42078** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42078)\n- **RHSA-2026:54757** · Red Hat · fixed in: Red Hat OpenStack Platform 16.2 · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54757)\n- **RHSA-2026:27076** · Red Hat · fixed in: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9 · released 2026-06-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:27076)\n- **RHSA-2026:28010** · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2026-06-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:28010)\n- **RHSA-2026:36796** · Red Hat · fixed in: RHEM 1.0 for RHEL 9 · released 2026-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:36796)\n- **RHSA-2026:39810** · Red Hat · fixed in: Red Hat OpenStack Services on OpenShift 18.0, 9Base-RHOSO-TOOLS-18 · released 2026-07-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:39810)\n- **RHSA-2026:34365** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:34365)\n- **RHSA-2026:20569** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-05-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:20569)\n- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, cert-manager Operator for Red Hat OpenShift, Confidential Compute Attestation, Deployment Validation Operator, External Secrets Operator for Red Hat OpenShift, ExternalDNS Operator, … · no fix planned: Confidential Compute Attestation, External Secrets Operator for Red Hat OpenShift, Gatekeeper 3, Migration Toolkit for Applications 8, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32281.json)\n\n**crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation** — rated Moderate by Red Hat. Released 2026-04-08, updated 2026-09-21.\n\nAffected:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- cert-manager Operator for Red Hat OpenShift\n- Confidential Compute Attestation\n- Deployment Validation Operator\n- External Secrets Operator for Red Hat OpenShift\n- ExternalDNS Operator\n- Fence Agents Remediation Operator\n- Gatekeeper 3\n- Logging Subsystem for Red Hat OpenShift\n- Machine Deletion Remediation Operator\n- Migration Toolkit for Applications 8\n- Multiarch Tuning Operator\n- Multicluster Engine for Kubernetes\n- Multicluster Global Hub\n- Node HealthCheck Operator\n- OpenShift Developer Tools and Services\n- OpenShift Pipelines\n- OpenShift Serverless\n- OpenShift Service Mesh 3\n- Power monitoring for Red Hat OpenShift\n- Red Hat 3scale API Management Platform 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Advanced Cluster Security 4\n- Red Hat AMQ Broker 7\n- Red Hat Ansible Automation Platform 2\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Apicurio Registry 2\n- Red Hat Certification Program for Red Hat Enterprise Linux 9\n- Red Hat Connectivity Link 1\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat JBoss Web Server 6\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Cluster Manager CLI\n- Red Hat OpenShift Container Platform 4\n- Red Hat Openshift Data Foundation 4\n- Red Hat OpenShift Dev Spaces\n- Red Hat OpenShift for Windows Containers\n- Red Hat OpenShift on AWS\n\nFixed:\n\n- Red Hat Ansible Automation Platform 2.6 for RHEL 10\n- RHEM 1.1 for RHEL 10\n- Red Hat Enterprise Linux Server (v. 7 ELS)\n- Red Hat Ansible Automation Platform 2.5 for RHEL 8\n- Red Hat OpenStack Platform 16.2\n- Red Hat Satellite 6.16 for RHEL 8\n- Red Hat Ansible Automation Platform 2.5 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6 for RHEL 9\n- Cryostat 4 on RHEL 9\n- RHEM 1.0 for RHEL 9\n- RHEM 1.1 for RHEL 9\n- Red Hat OpenStack Services on OpenShift 18.0\n- 9Base-RHOSO-TOOLS-18\n- Red Hat Satellite 6.16 for RHEL 9\n- Red Hat Satellite 6.19 for RHEL 9\n- Red Hat Enterprise Linux AppStream EUS (v. 10.0)\n- Red Hat Enterprise Linux AppStream (v. 10)\n- Red Hat Enterprise Linux AppStream (v. 8)\n- Red Hat Enterprise Linux AppStream AUS (v.8.6)\n- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)\n- Red Hat Enterprise Linux AppStream E4S (v.8.8)\n- Red Hat Enterprise Linux AppStream TUS (v.8.8)\n- Red Hat Enterprise Linux AppStream E4S (v.9.2)\n- Red Hat Enterprise Linux AppStream E4S (v.9.4)\n- Red Hat Enterprise Linux AppStream EUS (v.9.4)\n- Red Hat Enterprise Linux AppStream EUS (v.9.6)\n- Red Hat Enterprise Linux AppStream (v. 9)\n- Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)\n- Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)\n- Red Hat CodeReady Linux Builder EUS (v.9.6)\n- Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)\n- Cluster Observability Operator 1.5.0\n- Custom Metric Autoscaler 2.19\n- DevWorkspace Operator 0.42\n- HawtIO HawtIO 4.4.0\n- Logging Subsystem for Red Hat OpenShift 6.2\n- Logging Subsystem for Red Hat OpenShift 6.4\n- Logging Subsystem for Red Hat OpenShift 6.5\n- Logging for Red Hat OpenShift 6\n- Multicluster Global Hub 1.4.9\n\nNo fix planned:\n\n- Confidential Compute Attestation\n- External Secrets Operator for Red Hat OpenShift\n- Gatekeeper 3\n- Migration Toolkit for Applications 8\n- Red Hat 3scale API Management Platform 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat build of Apicurio Registry 2\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat Quay 3\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- cert-manager Operator for Red Hat OpenShift\n- Deployment Validation Operator\n- ExternalDNS Operator\n- Fence Agents Remediation Operator\n- Logging Subsystem for Red Hat OpenShift\n- Machine Deletion Remediation Operator\n- Multiarch Tuning Operator\n- Multicluster Engine for Kubernetes\n- Multicluster Global Hub\n- Node HealthCheck Operator\n- OpenShift Developer Tools and Services\n- OpenShift Pipelines\n- OpenShift Serverless\n- OpenShift Service Mesh 3\n- Power monitoring for Red Hat OpenShift\n- Red Hat Advanced Cluster Security 4\n- Red Hat AMQ Broker 7\n- Red Hat Ansible Automation Platform 2\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat Certification Program for Red Hat Enterprise Linux 9\n- Red Hat Connectivity Link 1\n- Red Hat JBoss Web Server 6\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Cluster Manager CLI\n- Red Hat OpenShift Container Platform 4\n- Red Hat Openshift Data Foundation 4\n- Red Hat OpenShift Dev Spaces\n- Red Hat OpenShift for Windows Containers\n\nNot affected:\n\n- Red Hat Ansible Automation Platform 2.6 for RHEL 10\n- RHEM 1.1 for RHEL 10\n- Red Hat Ansible Automation Platform 2.5 for RHEL 8\n- Red Hat OpenStack Platform 16.2\n- Red Hat Satellite 6.16 for RHEL 8\n- Red Hat Ansible Automation Platform 2.5 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6 for RHEL 9\n- Cryostat 4 on RHEL 9\n- RHEM 1.0 for RHEL 9\n- RHEM 1.1 for RHEL 9\n\n## Remediation\n\nFor details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:42079\nSee the following documentation for details on how to enable Red Hat Edge\nManager and more:\nhttps://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 https://access.redhat.com/errata/RHSA-2026:41019\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:16101\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2026-32281)\n\nAffected packages:\n\n- `stdlib >= 1.26.0-0, < 1.26.2`\n\nPatched in:\n\n- `stdlib 1.26.2`\n\nSource: https://osv.dev/vulnerability/GO-2026-4946","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":32.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":5083,"id":"CVE-2026-32281","ts":1788887248005,"field":"cvss","old":null,"new":"5.9"},{"seq":5082,"id":"CVE-2026-32281","ts":1788887248005,"field":"severity","old":"none","new":"medium"},{"seq":3966,"id":"CVE-2026-32281","ts":1788886363646,"field":"cvss","old":"5.9","new":null},{"seq":3965,"id":"CVE-2026-32281","ts":1788886363646,"field":"severity","old":"medium","new":"none"},{"seq":3153,"id":"CVE-2026-32281","ts":1788883133082,"field":"cvss","old":null,"new":"5.9"},{"seq":3152,"id":"CVE-2026-32281","ts":1788883133082,"field":"severity","old":"none","new":"medium"}]}