https://seclists.org/oss-sec/2026/q3/102: Go 1.26.5 and Go 1.25.12 fix CVE-2026-39822 & CVE-2026-42505
Published Jul 8, 2026
·Updated
Affected Software
2 affected components
Google Go=1.26.5
Google Go=1.25.12
Frequently Asked Questions
1
What is the severity of CVE-2026-39822?
CVE-2026-39822 is classified as a medium severity vulnerability.
2
What is the severity of CVE-2026-42505?
CVE-2026-42505 is classified as a low severity vulnerability.
3
How do I fix CVE-2026-39822?
To fix CVE-2026-39822, upgrade to Go version 1.26.5 or 1.25.12.
4
How do I fix CVE-2026-42505?
To fix CVE-2026-42505, upgrade to Go version 1.26.5 or 1.25.12.
5
What changes were made in Go versions 1.26.5 and 1.25.12?
Go versions 1.26.5 and 1.25.12 include fixes for CVE-2026-39822 and CVE-2026-42505.