RHSA-2026:60305: Important: go-toolset:rhel8 security, bug fix, and enhancement update
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. Security Fix(es): encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) Bug Fix(es) and Enhancement(s): Update Go to version 1.26.7+1 [rhel-8.10.z] (JIRA:RHEL-246426) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: go-toolset:rhel8 security, bug fix, and enhancement update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/delveto a version that resolves this vulnerability.Fixed in 1.26.1-1.module+el8.10.0+24516+40554724 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.26.7-1.module+el8.10.0+24751+b3673b3e - Upgrade
Upgrade
redhat/golang-docsto a version that resolves this vulnerability.Fixed in 1.26.7-1.module+el8.10.0+24751+b3673b3e - Upgrade
Upgrade
redhat/golang-miscto a version that resolves this vulnerability.Fixed in 1.26.7-1.module+el8.10.0+24751+b3673b3e - Upgrade
Upgrade
redhat/golang-srcto a version that resolves this vulnerability.Fixed in 1.26.7-1.module+el8.10.0+24751+b3673b3e - Upgrade
Upgrade
redhat/golang-teststo a version that resolves this vulnerability.Fixed in 1.26.7-1.module+el8.10.0+24751+b3673b3e - Upgrade
Upgrade
redhat/delve-debuginfoto a version that resolves this vulnerability.Fixed in 1.26.1-1.module+el8.10.0+24516+40554724 - Upgrade
Upgrade
redhat/delve-debugsourceto a version that resolves this vulnerability.Fixed in 1.26.1-1.module+el8.10.0+24516+40554724 - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.26.7-1.module+el8.10.0+24751+b3673b3e - Upgrade
Upgrade
redhat/golang-binto a version that resolves this vulnerability.Fixed in 1.26.7-1.module+el8.10.0+24751+b3673b3e - Upgrade
Upgrade
redhat/golang-raceto a version that resolves this vulnerability.Fixed in 1.26.7-1.module+el8.10.0+24751+b3673b3e - Upgrade
Upgrade
redhat/delveto a version that resolves this vulnerability.Fixed in 1.26.1-1.module+el8.10.0+24516+40554724.aa - Upgrade
Upgrade
redhat/delve-debuginfoto a version that resolves this vulnerability.Fixed in 1.26.1-1.module+el8.10.0+24516+40554724.aa - Upgrade
Upgrade
redhat/delve-debugsourceto a version that resolves this vulnerability.Fixed in 1.26.1-1.module+el8.10.0+24516+40554724.aa - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.26.7-1.module+el8.10.0+24751+b3673b3e.aa - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.26.7-1.module+el8.10.0+24751+b3673b3e.aa - Upgrade
Upgrade
redhat/golang-binto a version that resolves this vulnerability.Fixed in 1.26.7-1.module+el8.10.0+24751+b3673b3e.aa - Upgrade
Upgrade
redhat/golang-raceto a version that resolves this vulnerability.Fixed in 1.26.7-1.module+el8.10.0+24751+b3673b3e.aa - Upgrade
Upgrade
go-toolset:rhel8to a version that resolves this vulnerability.Fixed in 1.26.7+1 [rhel-8.10.z]Patch JIRA:RHEL-246426 - Compensating control
If upgrading Go is not immediately possible, mitigate CVE-2026-33818 (encoding/asn1 excessive recursion in Unmarshal), CVE-2026-56862 (crypto/tls indefinite KeyUpdate messages), CVE-2026-56859 (encoding/xml decoding recursion depth), CVE-2026-56858 (html/template pathological input XSS), CVE-2026-56853 (unencrypted HTTP/2 DoS), and CVE-2026-56860 (net/url quadratic path resolution) by placing/ensuring a compensating control that limits abusive/untrusted inputs to the affected endpoints (e.g., rate limiting and/or strict request validation) until the Go update is applied.
Event History
Frequently Asked Questions
Which security issues are addressed by this update?
The update addresses denial-of-service issues in encoding/asn1, net/url, net/http, crypto/tls, and encoding/xml, plus a cross-site scripting issue in html/template. The listed CVEs are CVE-2026-33818, CVE-2026-56860, CVE-2026-56853, CVE-2026-56858, CVE-2026-56862, and CVE-2026-56859.
What Go version does the update provide?
The update moves Go Toolset to Go version 1.26.7+1 for rhel-8.10.z.
Which installed components should be reviewed when assessing exposure?
Review installations of go-toolset, golang, golang-bin, golang-race, and delve. The advisory also lists the associated delve debug packages.