RHSA-2026:57649: Important: golang security update
Important: golang security update
Other sources
The golang packages provide the Go programming language compiler.Security Fix(es): net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy (CVE-2026-42501) html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content (CVE-2026-39823) cmd/go: golang: Go 'go bug' command: Arbitrary file overwrite via symlink attack (CVE-2026-39819) net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGSMAXFRAMESIZE frame (CVE-2026-33814) net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (CVE-2026-39825) cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction (CVE-2026-39817) html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping (CVE-2026-39826) golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) net/textproto: golang: Golang net/textproto: Misleading error messages via input injection (CVE-2026-42507) crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) golang: Go os.Root: Symlink following vulnerability allows directory traversal (CVE-2026-39822) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.26.5-1.el9_4 - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.26.5-1.el9_4 - Upgrade
Upgrade
redhat/golang-binto a version that resolves this vulnerability.Fixed in 1.26.5-1.el9_4 - Upgrade
Upgrade
redhat/golang-docsto a version that resolves this vulnerability.Fixed in 1.26.5-1.el9_4 - Upgrade
Upgrade
redhat/golang-miscto a version that resolves this vulnerability.Fixed in 1.26.5-1.el9_4 - Upgrade
Upgrade
redhat/golang-raceto a version that resolves this vulnerability.Fixed in 1.26.5-1.el9_4 - Upgrade
Upgrade
redhat/golang-srcto a version that resolves this vulnerability.Fixed in 1.26.5-1.el9_4 - Upgrade
Upgrade
redhat/golang-teststo a version that resolves this vulnerability.Fixed in 1.26.5-1.el9_4 - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.26.5-1.el9_4.aa - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.26.5-1.el9_4.aa - Upgrade
Upgrade
redhat/golang-binto a version that resolves this vulnerability.Fixed in 1.26.5-1.el9_4.aa - Upgrade
Upgrade
redhat/golang-raceto a version that resolves this vulnerability.Fixed in 1.26.5-1.el9_4.aa
Event History
Frequently Asked Questions
Which deployments should be prioritized for this update?
Prioritize systems using Red Hat golang, go-toolset, golang-bin, or golang-race packages, particularly where Go applications parse email, serve HTTP/2, use reverse proxies, render HTML templates, perform CNAME lookups, or retrieve modules through a module proxy. The advisory also applies to the listed Red Hat Enterprise Linux Update Services for SAP Solutions and Extended Life Cycle offerings on x86_64, ARM 64, and Power LE.
What attacker-controlled inputs or conditions are relevant?
Several issues require crafted network or application inputs, including pathological email addresses, malformed HTTP/2 SETTINGS_MAX_FRAME_SIZE frames, long CNAME responses, and hidden query parameters sent through a ReverseProxy. Other issues involve a malicious module proxy, a malicious archive, or symlink manipulation affecting Go tooling commands.
Are fixed package versions or configuration workarounds provided?
No fixed package versions, default-configuration status, detection methods, or interim mitigations are included in the provided advisory data. The available remediation information is limited to the security update and the affected package families.