DEBIAN-CVE-2026-27138

Source
https://security-tracker.debian.org/tracker/CVE-2026-27138
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-27138.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-27138
Upstream
  • CVE-2026-27138
Published
2026-03-06T22:16:00.963Z
Modified
2026-03-13T06:41:35.602806Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the chain has excluded name constraints. This can crash programs that are either directly verifying X.509 certificate chains, or those that use TLS.

References

Affected packages

Debian:14 / golang-1.26

Package

Name
golang-1.26
Purl
pkg:deb/debian/golang-1.26?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.26.1-1

Affected versions

1.*
1.26~rc2-1
1.26~rc3-1
1.26~rc3-2
1.26.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-27138.json"