CVE Vulnerabilities

CVE-2026-42508

Improper Certificate Validation

Published: May 22, 2026 | Modified: May 28, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.4 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Previously, a revoked SignatureKey belonging to a CA was not correctly checked for revocation. Now, both the key and key.SignatureKey are checked for @revoked.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
CryptoGolang*0.52.0 (excluding)
Golang-go.cryptoUbuntuesm-apps/bionic*
Golang-go.cryptoUbuntuesm-apps/focal*
Golang-go.cryptoUbuntuesm-apps/jammy*
Golang-go.cryptoUbuntuesm-apps/noble*
Golang-go.cryptoUbuntuesm-apps/resolute*
Golang-go.cryptoUbuntujammy*
Golang-go.cryptoUbuntunoble*
Golang-go.cryptoUbuntuquesting*
Golang-go.cryptoUbunturesolute*
Golang-go.cryptoUbuntuupstream*
LxdUbuntuesm-infra-legacy/xenial*
LxdUbuntuesm-infra/bionic*

Potential Mitigations

References