RHSA-2026:49703: Important: delve security, bug fix, and enhancement update
Delve is a debugger for the Go programming language. The goal of the project is to provide a simple, full featured debugging tool for Go. Delve should be easy to invoke and easy to use. Chances are if you're using a debugger, things aren't going your way. With that in mind, Delve should stay out of your way as much as possible.Security Fix(es): net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) Bug Fix(es) and Enhancement(s): Update Delve to 1.26 [rhel-10.0.z] (JIRA:RHEL-213072) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: delve security, bug fix, and enhancement update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/delveto a version that resolves this vulnerability.Fixed in 1.26.1-1.el10_0 - Upgrade
Upgrade
redhat/delve-debuginfoto a version that resolves this vulnerability.Fixed in 1.26.1-1.el10_0 - Upgrade
Upgrade
redhat/delve-debugsourceto a version that resolves this vulnerability.Fixed in 1.26.1-1.el10_0 - Upgrade
Upgrade
redhat/delveto a version that resolves this vulnerability.Fixed in 1.26.1-1.el10_0.aa - Upgrade
Upgrade
redhat/delve-debuginfoto a version that resolves this vulnerability.Fixed in 1.26.1-1.el10_0.aa - Upgrade
Upgrade
redhat/delve-debugsourceto a version that resolves this vulnerability.Fixed in 1.26.1-1.el10_0.aa - Upgrade
Upgrade
delveto a version that resolves this vulnerability.Fixed in 1.26Patch JIRA:RHEL-213072 - Upgrade
Upgrade
golang crypto/x509to a version that resolves this vulnerability.Patch CVE-2026-27145 - Upgrade
Upgrade
golang netto a version that resolves this vulnerability.Patch CVE-2026-33811
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:49703?
The severity of RHSA-2026:49703 is high with a score of 7.
How do I fix RHSA-2026:49703?
To fix RHSA-2026:49703, you should update your Delve package to the latest version provided by Red Hat.
What does RHSA-2026:49703 address?
RHSA-2026:49703 addresses security vulnerabilities and bugs in the Delve debugger for the Go programming language.
Which systems are affected by RHSA-2026:49703?
RHSA-2026:49703 affects multiple Red Hat Enterprise Linux versions including Power, ARM 64, and x86_64 architectures.
When was RHSA-2026:49703 published?
RHSA-2026:49703 was published on August 3, 2026.