UNKNOWN Go
Usage of ExtKeyUsageAny disables policy validation in crypto/x509
GO-2025-3749 · BIT-golang-2025-22874 · CVE-2025-22874
Published · Modified
Description
Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes