CVE-2026-32280: CWE-770: Allocation of Resources Without Limits or Throttling in Go standard library crypto/x509
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
AI Analysis
Technical Summary
The Red Hat build of Cryostat 4 on RHEL 9 is affected by multiple vulnerabilities in Go language libraries. CVE-2026-32280 describes a denial of service vulnerability in certificate chain building within the crypto/x509 package. CVE-2026-32283 involves a denial of service via multiple TLS 1.3 key update messages in the crypto/tls package. CVE-2026-33810 details a certificate validation bypass caused by incorrect DNS constraint application in crypto/x509. CVE-2026-32282 concerns the internal syscall/unix package where Root.Chmod can follow symlinks outside the root directory. These vulnerabilities collectively impact the security of TLS communications and system file permissions in affected Cryostat builds. Red Hat has released security updates to address these issues.
Potential Impact
The vulnerabilities can lead to denial of service conditions in TLS communications and certificate chain validation, potentially disrupting secure connections. The certificate validation bypass may allow improper acceptance of TLS certificates, weakening security guarantees. The Root.Chmod symlink issue could allow unauthorized modification of files outside the intended root directory, posing a risk to system integrity. These impacts affect the confidentiality, integrity, and availability of systems running the affected Cryostat versions.
Mitigation Recommendations
Red Hat has released security updates for the Red Hat build of Cryostat 4 on RHEL 9 that address these vulnerabilities. Users should apply the available updates as per Red Hat's guidance to remediate these issues. Before applying this update, ensure all previously released errata relevant to your system have been applied. Refer to Red Hat's official advisory and update instructions at https://access.redhat.com/articles/11258 for detailed remediation steps.
CVE-2026-32280: CWE-770: Allocation of Resources Without Limits or Throttling in Go standard library crypto/x509
Description
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
CVSS v3.1
Score 7.5high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat build of Cryostat 4 on RHEL 9 is affected by multiple vulnerabilities in Go language libraries. CVE-2026-32280 describes a denial of service vulnerability in certificate chain building within the crypto/x509 package. CVE-2026-32283 involves a denial of service via multiple TLS 1.3 key update messages in the crypto/tls package. CVE-2026-33810 details a certificate validation bypass caused by incorrect DNS constraint application in crypto/x509. CVE-2026-32282 concerns the internal syscall/unix package where Root.Chmod can follow symlinks outside the root directory. These vulnerabilities collectively impact the security of TLS communications and system file permissions in affected Cryostat builds. Red Hat has released security updates to address these issues.
Potential Impact
The vulnerabilities can lead to denial of service conditions in TLS communications and certificate chain validation, potentially disrupting secure connections. The certificate validation bypass may allow improper acceptance of TLS certificates, weakening security guarantees. The Root.Chmod symlink issue could allow unauthorized modification of files outside the intended root directory, posing a risk to system integrity. These impacts affect the confidentiality, integrity, and availability of systems running the affected Cryostat versions.
Mitigation Recommendations
Red Hat has released security updates for the Red Hat build of Cryostat 4 on RHEL 9 that address these vulnerabilities. Users should apply the available updates as per Red Hat's guidance to remediate these issues. Before applying this update, ensure all previously released errata relevant to your system have been applied. Refer to Red Hat's official advisory and update instructions at https://access.redhat.com/articles/11258 for detailed remediation steps.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:20608
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-32283"]
- Cvss Version
- null
Threat ID: 6a16097ee29bf47b5064a9c0
Added to database: 05/26/2026, 20:58:38 UTC
Last enriched: 07/30/2026, 11:11:04 UTC
Last updated: 07/31/2026, 21:28:51 UTC
Views: 90
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.