CVE-2024-24783: Go Standard Library crypto/x509
Medium severity, CVSS 5.9. EPSS: 0.7% chance of exploitation in the next 30 days.
Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.
Affected products
- Go Standard Library crypto/x509: before 1.21.8 (fixed in 1.21.8); from 1.22.0-0, before 1.22.1 (fixed in 1.22.1)
Published 2024-03-05. Last modified 2026-06-17.