CVE-2026-27138 affects multiple packages. Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the chain has excluded name constraints. See references for individual vulnerability details.