CVE-2020-14039: Golang Go

Medium severity, CVSS 5.3. EPSS: 1.8% chance of exploitation in the next 30 days.

In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.

Affected products

  • Golang Go: before 1.13.13 (fixed in 1.13.13); from 1.14.0, before 1.14.5 (fixed in 1.14.5)
  • Opensuse Leap: version 15.1 only; version 15.2 only

Published 2020-07-17. Last modified 2026-06-17.