CVE Vulnerabilities

CVE-2025-61727

Improper Certificate Validation

Published: Dec 03, 2025 | Modified: Dec 18, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
GoGolang*1.24.11 (excluding)
GoGolang1.25 (including)1.25.5 (excluding)
Cert-manager operator for Red Hat OpenShift 1.18RedHatcert-manager/jetstack-cert-manager-rhel9:sha256:3ca7fb070c05efc25fe53af6fc922875ecb9d11943d3c243b2840d7ca2b1aa33*
Cert-manager operator for Red Hat OpenShift 1.18RedHatcert-manager/jetstack-cert-manager-rhel9:sha256:77f4d70980abe59f1e69bf38bfeeeed0b84b27fe9ae3286666d01a0c8aa6b067*
Cert-manager operator for Red Hat OpenShift 1.18RedHatcert-manager/jetstack-cert-manager-acmesolver-rhel9:sha256:155383c4664ea3ed18d0f079be720ad68a5de044448a744d7579af7ff0fc7e0a*
Cert-manager operator for Red Hat OpenShift 1.18RedHatcert-manager/jetstack-cert-manager-rhel9:sha256:63f4e63f3249b6271041d31fcfbf69c3ad699d319302e8fdb2bff5e1b1418707*
Golang-1.24Ubuntuplucky*

Potential Mitigations

References