An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 03 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 03 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com. | |
| Title | Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509 | |
| References |
|
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-12-03T22:06:17.007Z
Reserved: 2025-09-30T15:05:03.605Z
Link: CVE-2025-61727
Updated: 2025-12-03T21:45:44.520Z
Status : Received
Published: 2025-12-03T20:16:25.607
Modified: 2025-12-03T22:15:51.510
Link: CVE-2025-61727
No data.
OpenCVE Enrichment
No data.