Launch Week Day 1: Announcing Security Design Review
UNKNOWN Go

Usage of ExtKeyUsageAny disables policy validation in crypto/x509

GO-2025-3749 · BIT-golang-2025-22874 · CVE-2025-22874

Published · Modified

Description

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

Ready to move

Start Securing

Free, no credit card | First findings in minutes