---
id: CVE-2025-22874
title: >-
  crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509
  (CVE-2025-22874)
summary: >-
  A flaw was found in Go's crypto/x509 package. This vulnerability allows
  improper certificate validation, bypassing policy constraints via using
  ExtKeyUsageAny in VerifyOptions.KeyUsages.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cvssSource: vendor
cwe: CWE-295
vendor: Red Hat
product: Red Hat OpenShift Container Platform 4.20
affected:
  - assisted_installer_for_red_hat_openshift_container_platform 2
  - builds_for_red_hat_openshift
  - cert_manager_operator_for_red_hat_openshift
  - confidential_compute_attestation
  - deployment_validation_operator
  - external_secrets_operator_for_red_hat_openshift_tech_preview
  - openshift_lightspeed
  - openshift_serverless
  - enterprise_linux 10
  - enterprise_linux 8
  - enterprise_linux 9
  - openshift_ai_rhoai
  - openshift_dev_workspaces_operator
  - openshift_distributed_tracing 3
  - runtimes_inventory_operator
  - trusted_application_pipeline
  - trusted_artifact_signer
  - zero_trust_workload_identity_manager_tech_preview
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_e4s_v_9_4
  - enterprise_linux_appstream_v_9
  - builds_for_red_hat_openshift 1.5.2
  - lightspeed_formerly_insights_for_runtimes 1.0
  - openshift_container_platform 4.20
  - openshift_gitops 1.16
  - openshift_gitops 1.17
  - openshift_distributed_tracing 3.7.0
  - trusted_artifact_signer 1.2
patched:
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_e4s_v_9_4
  - enterprise_linux_appstream_v_9
  - builds_for_red_hat_openshift 1.5.2
  - lightspeed_formerly_insights_for_runtimes 1.0
  - openshift_container_platform 4.20
  - openshift_gitops 1.16
  - openshift_gitops 1.17
  - openshift_distributed_tracing 3.7.0
  - trusted_artifact_signer 1.2
published: '2025-06-11'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:01:21+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-22874.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-22874.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-22874'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2372320'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-22874'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-22874'
  - url: 'https://go.dev/cl/670375'
  - url: 'https://go.dev/issue/73612'
  - url: 'https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A'
  - url: 'https://pkg.go.dev/vuln/GO-2025-3749'
  - url: 'https://access.redhat.com/errata/RHSA-2025:10677'
  - url: 'https://access.redhat.com/errata/RHSA-2026:47719'
  - url: 'https://access.redhat.com/errata/RHSA-2026:47712'
  - url: 'https://access.redhat.com/errata/RHSA-2025:10676'
  - url: 'https://access.redhat.com/errata/RHSA-2025:13931'
  - url: 'https://access.redhat.com/errata/RHSA-2025:23236'
  - url: 'https://access.redhat.com/errata/RHSA-2025:19003'
  - url: 'https://access.redhat.com/errata/RHSA-2025:19890'
  - url: 'https://access.redhat.com/errata/RHSA-2025:17730'
  - url: 'https://access.redhat.com/errata/RHSA-2025:17731'
  - url: 'https://access.redhat.com/errata/RHSA-2025:17043'
  - url: 'https://access.redhat.com/errata/RHSA-2025:14470'
  - url: 'https://access.redhat.com/errata/RHSA-2025:14473'
  - url: 'https://access.redhat.com/errata/RHSA-2025:14472'
  - url: 'https://access.redhat.com/errata/RHSA-2025:14476'
  - url: 'https://access.redhat.com/errata/RHSA-2025:14484'
  - url: 'https://access.redhat.com/errata/RHSA-2025:14479'
  - url: 'https://access.redhat.com/errata/RHSA-2025:14481'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00374
epssPercentile: 0.28577
aliases:
  - GO-2025-3749
  - BIT-golang-2025-22874
ecosystem: go
ingestedAt: '2026-08-27T19:27:47.783Z'
---

## Overview

A flaw was found in Go's crypto/x509 package. This vulnerability allows improper certificate validation, bypassing policy constraints via using ExtKeyUsageAny in VerifyOptions.KeyUsages.

## Vendor advisories

- **RHSA-2025:10677** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2025-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2025:10677)
- **RHSA-2026:47719** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:47719)
- **RHSA-2026:47712** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:47712)
- **RHSA-2025:10676** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2025-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2025:10676)
- **RHSA-2025:13931** · Red Hat · fixed in: Builds for Red Hat OpenShift 1.5.2 · released 2025-08-14 · [advisory](https://access.redhat.com/errata/RHSA-2025:13931)
- **RHSA-2025:23236** · Red Hat · fixed in: Red Hat Lightspeed (formerly Insights) for Runtimes 1.0 · released 2025-12-16 · [advisory](https://access.redhat.com/errata/RHSA-2025:23236)
- **RHSA-2025:19003** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.20 · released 2025-10-30 · [advisory](https://access.redhat.com/errata/RHSA-2025:19003)
- **RHSA-2025:19890** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.20 · released 2025-11-11 · [advisory](https://access.redhat.com/errata/RHSA-2025:19890)
- **RHSA-2025:17730** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.16 · released 2025-10-09 · [advisory](https://access.redhat.com/errata/RHSA-2025:17730)
- **RHSA-2025:17731** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.17 · released 2025-10-09 · [advisory](https://access.redhat.com/errata/RHSA-2025:17731)
- **RHSA-2025:17043** · Red Hat · fixed in: Red Hat OpenShift distributed tracing 3.7.0 · released 2025-09-30 · [advisory](https://access.redhat.com/errata/RHSA-2025:17043)
- **Red Hat VEX** · Important · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, cert-manager Operator for Red Hat OpenShift, Confidential Compute Attestation, Deployment Validation Operator, external secrets operator for Red Hat OpenShift - Tech Preview, … · no fix planned: Builds for Red Hat OpenShift, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Runtimes Inventory Operator, … · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-22874.json)

**crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509** — rated Important by Red Hat. Released 2025-06-11, updated 2026-09-10.

Affected:

- Assisted Installer for Red Hat OpenShift Container Platform 2
- Builds for Red Hat OpenShift
- cert-manager Operator for Red Hat OpenShift
- Confidential Compute Attestation
- Deployment Validation Operator
- external secrets operator for Red Hat OpenShift - Tech Preview
- OpenShift Lightspeed
- OpenShift Serverless
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Dev Workspaces Operator
- Red Hat OpenShift distributed tracing 3
- Red Hat Runtimes Inventory Operator
- Red Hat Trusted Application Pipeline
- Red Hat Trusted Artifact Signer
- Zero Trust Workload Identity Manager - Tech Preview

Fixed:

- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream E4S (v.9.2)
- Red Hat Enterprise Linux AppStream E4S (v.9.4)
- Red Hat Enterprise Linux AppStream (v. 9)
- Builds for Red Hat OpenShift 1.5.2
- Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- Red Hat OpenShift Container Platform 4.20
- Red Hat OpenShift GitOps 1.16
- Red Hat OpenShift GitOps 1.17
- Red Hat OpenShift distributed tracing 3.7.0
- Red Hat Trusted Artifact Signer 1.2

No fix planned:

- Builds for Red Hat OpenShift
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat Runtimes Inventory Operator
- Zero Trust Workload Identity Manager - Tech Preview
- Assisted Installer for Red Hat OpenShift Container Platform 2
- cert-manager Operator for Red Hat OpenShift
- Confidential Compute Attestation
- Deployment Validation Operator
- external secrets operator for Red Hat OpenShift - Tech Preview
- OpenShift Lightspeed
- OpenShift Serverless
- Red Hat Enterprise Linux 8
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Dev Workspaces Operator
- Red Hat OpenShift distributed tracing 3
- Red Hat Trusted Application Pipeline
- Red Hat Trusted Artifact Signer

Not affected:

- Builds for Red Hat OpenShift 1.5.2
- Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- Red Hat OpenShift Container Platform 4.20
- Red Hat OpenShift GitOps 1.16
- Red Hat OpenShift GitOps 1.17
- Red Hat OpenShift distributed tracing 3.7.0
- Red Hat Trusted Artifact Signer 1.2
- Custom Metric Autoscaler operator for Red Hat Openshift
- Multiarch Tuning Operator
- NBDE Tang Server

## Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:10677
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:47719
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:47712

## Package advisory (CVE-2025-22874)

Affected packages:

- `stdlib >= 1.24.0-0, < 1.24.4`

Patched in:

- `stdlib 1.24.4`

Source: https://osv.dev/vulnerability/GO-2025-3749
