CVE-2025-61727: Golang Go

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.

Affected products

  • Golang Go: before 1.24.11 (fixed in 1.24.11); from 1.25, before 1.25.5 (fixed in 1.25.5)

Published 2025-12-03. Last modified 2026-06-17.