Validating certificate chains which use policies is...
High severity
Unreviewed
Published
Apr 8, 2026
to the GitHub Advisory Database
•
Updated Apr 16, 2026
Description
Published by the National Vulnerability Database
Apr 8, 2026
Published to the GitHub Advisory Database
Apr 8, 2026
Last updated
Apr 16, 2026
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
References