CVE-2026-32280: Golang Go

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.

Affected products

  • Golang Go: before 1.25.9 (fixed in 1.25.9); from 1.26.0, before 1.26.2 (fixed in 1.26.2)

Published 2026-04-08. Last modified 2026-09-18.