—
GO-2026-4946
Inefficient policy validation in crypto/x509
Details
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service.
This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
Are you affected?
Enter the version of the package you're using.