Information on source package golang-1.26

Available versions

ReleaseVersion
forky1.26.5-1
sid1.26.5-1

Resolved issues

BugDescription
CVE-2026-42507When returning errors, functions in the net/textproto package would in ...
CVE-2026-42505Handshakes which used Encrypted Client Hello could be de-anonymized by ...
CVE-2026-42504Decoding a maliciously-crafted MIME header containing many invalid enc ...
CVE-2026-42501A malicious module proxy can exploit a flaw in the go command's valida ...
CVE-2026-42499Pathological inputs could cause DoS through consumePhrase when parsing ...
CVE-2026-39836The Dial and LookupPort functions panic on Windows when provided with ...
CVE-2026-39826If a trusted template author were to write a <script> tag containing a ...
CVE-2026-39825ReverseProxy can forward queries containing parameters not visible to ...
CVE-2026-39823CVE-2026-27142 fixed a vulnerability in which URLs were not correctly ...
CVE-2026-39822On Unix systems, opening a file in an os.Root improperly follows symli ...
CVE-2026-39820Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
CVE-2026-39819The "go bug" command writes to two files with predictable names in the ...
CVE-2026-39817The "go tool pack" subcommand (usually used only by the compiler as an ...
CVE-2026-33811When using LookupCNAME with the cgo DNS resolver, a very long CNAME re ...
CVE-2026-33810When verifying a certificate chain containing excluded DNS constraints ...
CVE-2026-32289Context was not properly tracked across template branches for JS templ ...
CVE-2026-32288tar.Reader can allocate an unbounded amount of memory when reading a m ...
CVE-2026-32283If one side of the TLS connection sends multiple key update messages p ...
CVE-2026-32282On Linux, if the target of Root.Chmod is replaced with a symlink while ...
CVE-2026-32281Validating certificate chains which use policies is unexpectedly ineff ...
CVE-2026-32280During chain building, the amount of work that is done is not correctl ...
CVE-2026-27145(*x509.Certificate).VerifyHostname previously called matchHostnames in ...
CVE-2026-27144The compiler is meant to unwrap pointers which are the operands of a m ...
CVE-2026-27143Arithmetic over induction variables in loops were not correctly checke ...
CVE-2026-27142Actions which insert URLs into the content attribute of HTML meta tags ...
CVE-2026-27140SWIG file names containing 'cgo' and well-crafted payloads could lead ...
CVE-2026-27139On Unix platforms, when listing the contents of a directory using File ...
CVE-2026-27138Certificate verification can panic when a certificate in the chain has ...
CVE-2026-27137When verifying a certificate chain which contains a certificate contai ...
CVE-2026-25679url.Parse insufficiently validated the host/authority component and ac ...

Search for package or bug name: Reporting problems