| Bug | Description |
|---|
| CVE-2026-42507 | When returning errors, functions in the net/textproto package would in ... |
| CVE-2026-42505 | Handshakes which used Encrypted Client Hello could be de-anonymized by ... |
| CVE-2026-42504 | Decoding a maliciously-crafted MIME header containing many invalid enc ... |
| CVE-2026-42501 | A malicious module proxy can exploit a flaw in the go command's valida ... |
| CVE-2026-42499 | Pathological inputs could cause DoS through consumePhrase when parsing ... |
| CVE-2026-39836 | The Dial and LookupPort functions panic on Windows when provided with ... |
| CVE-2026-39826 | If a trusted template author were to write a <script> tag containing a ... |
| CVE-2026-39825 | ReverseProxy can forward queries containing parameters not visible to ... |
| CVE-2026-39823 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly ... |
| CVE-2026-39822 | On Unix systems, opening a file in an os.Root improperly follows symli ... |
| CVE-2026-39820 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ... |
| CVE-2026-39819 | The "go bug" command writes to two files with predictable names in the ... |
| CVE-2026-39817 | The "go tool pack" subcommand (usually used only by the compiler as an ... |
| CVE-2026-33811 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME re ... |
| CVE-2026-33810 | When verifying a certificate chain containing excluded DNS constraints ... |
| CVE-2026-32289 | Context was not properly tracked across template branches for JS templ ... |
| CVE-2026-32288 | tar.Reader can allocate an unbounded amount of memory when reading a m ... |
| CVE-2026-32283 | If one side of the TLS connection sends multiple key update messages p ... |
| CVE-2026-32282 | On Linux, if the target of Root.Chmod is replaced with a symlink while ... |
| CVE-2026-32281 | Validating certificate chains which use policies is unexpectedly ineff ... |
| CVE-2026-32280 | During chain building, the amount of work that is done is not correctl ... |
| CVE-2026-27145 | (*x509.Certificate).VerifyHostname previously called matchHostnames in ... |
| CVE-2026-27144 | The compiler is meant to unwrap pointers which are the operands of a m ... |
| CVE-2026-27143 | Arithmetic over induction variables in loops were not correctly checke ... |
| CVE-2026-27142 | Actions which insert URLs into the content attribute of HTML meta tags ... |
| CVE-2026-27140 | SWIG file names containing 'cgo' and well-crafted payloads could lead ... |
| CVE-2026-27139 | On Unix platforms, when listing the contents of a directory using File ... |
| CVE-2026-27138 | Certificate verification can panic when a certificate in the chain has ... |
| CVE-2026-27137 | When verifying a certificate chain which contains a certificate contai ... |
| CVE-2026-25679 | url.Parse insufficiently validated the host/authority component and ac ... |