Loading
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
Use CWE-295, Golang vendor hub and Go product page to widen CVE-2026-33810 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-27143, CVE-2026-27140 and CVE-2026-32283 for nearby disclosures in the same product family.