CRITICAL9.1
GHSA-5cgq-3rg8-m6cv
golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status
Quick fix
GHSA-5cgq-3rg8-m6cv — golang.org/x/crypto: upgrade to the fixed version with the command below.
go get golang.org/x/crypto@v0.52.0Details
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-42508[ADVISORY]
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42508.json[WEB]
- https://pkg.go.dev/vuln/GO-2026-5021[WEB]
- https://groups.google.com/g/golang-announce/c/a082jnz-LvI[WEB]
- https://go.dev/issue/79568[WEB]
- https://go.dev/cl/781220[WEB]
- https://cs.opensource.google/go/x/crypto[PACKAGE]
- https://bugzilla.redhat.com/show_bug.cgi?id=2480688[WEB]
- https://access.redhat.com/security/cve/CVE-2026-42508[WEB]
- https://access.redhat.com/errata/RHSA-2026:41066[WEB]
- https://access.redhat.com/errata/RHSA-2026:41064[WEB]
- https://access.redhat.com/errata/RHSA-2026:41036[WEB]
- https://access.redhat.com/errata/RHSA-2026:41031[WEB]
- https://access.redhat.com/errata/RHSA-2026:41019[WEB]
- https://access.redhat.com/errata/RHSA-2026:40945[WEB]
- https://access.redhat.com/errata/RHSA-2026:40262[WEB]
- https://access.redhat.com/errata/RHSA-2026:40138[WEB]
- https://access.redhat.com/errata/RHSA-2026:40118[WEB]
- https://access.redhat.com/errata/RHSA-2026:37387[WEB]
- https://access.redhat.com/errata/RHSA-2026:37123[WEB]
- https://access.redhat.com/errata/RHSA-2026:37072[WEB]
- https://access.redhat.com/errata/RHSA-2026:36808[WEB]
- https://access.redhat.com/errata/RHSA-2026:36797[WEB]
- https://access.redhat.com/errata/RHSA-2026:36796[WEB]
- https://access.redhat.com/errata/RHSA-2026:36651[WEB]
- https://access.redhat.com/errata/RHSA-2026:36648[WEB]
- https://access.redhat.com/errata/RHSA-2026:35833[WEB]
- https://access.redhat.com/errata/RHSA-2026:26547[WEB]
- https://access.redhat.com/errata/RHSA-2026:26546[WEB]
- https://access.redhat.com/errata/RHSA-2026:23264[WEB]
- https://access.redhat.com/errata/RHSA-2026:23262[WEB]