Loading HuntDB...

GHSA-3q2c-pvp5-3cqp

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.

Related CVEs

Key Information

GHSA ID
GHSA-3q2c-pvp5-3cqp
Published
March 6, 2024 12:31 AM
Last Modified
November 5, 2024 6:31 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 18, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.