certificate-parsing
×
bug-bounty
1307
exploit
735
google
718
microsoft
646
malware
554
xss
551
rce
485
facebook
433
cve
425
apple
353
supply-chain
305
writeup
283
node
230
cloudflare
194
phishing
186
web3
184
browser
174
account-takeover
170
aws
162
reverse-engineering
150
dos
149
cloud
148
sqli
143
csrf
140
privilege-escalation
127
8
0
Daniel Mangum demonstrates a critical vulnerability in Go's X.509 certificate verification where certificates differing by only two bytes (0x13 vs 0x0c ASN.1 tag bytes) pass or fail verification, revealing a tag-confusion bug in Go's certificate parsing that OpenSSL accepts correctly.