[Apollo] Advisories Statistics light light Login

RLSA-2026:22112

Security Mirrored from RHSA-2026:22112
Issued at: 2026-08-26
Updated at: 2026-08-26

Advisory content derived from Red Hat RHSA-2026:22112, © Red Hat, Inc., used under CC BY 4.0, with modifications.

Synopsis

Important: go-toolset:rhel8 security update



Description

Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.

Security Fix(es):

* net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)

* cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy (CVE-2026-42501)

* html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content (CVE-2026-39823)

* cmd/go: golang: Go 'go bug' command: Arbitrary file overwrite via symlink attack (CVE-2026-39819)

* net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814)

* net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)

* net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)

* net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (CVE-2026-39825)

* cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction (CVE-2026-39817)

* html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping (CVE-2026-39826)

* net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows (CVE-2026-39836)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 8 aarch64

Fixes

2467809 2467810 2467811 2467813 2467815 2467820 2467822 2467823 2467825 2467826 2467827

CVEs

CVE-2026-33811 CVE-2026-33814 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501

Affected packages

Rocky Linux 8 aarch64 - AppStream

delve-0:1.25.2-1.module+el8.10.0+40035+ee0a7047.aarch64.rpm delve-0:1.25.2-1.module+el8.10.0+40035+ee0a7047.src.rpm delve-debuginfo-0:1.25.2-1.module+el8.10.0+40035+ee0a7047.aarch64.rpm delve-debugsource-0:1.25.2-1.module+el8.10.0+40035+ee0a7047.aarch64.rpm golang-0:1.25.10-1.module+el8.10.0+40200+0fd0f175.aarch64.rpm golang-0:1.25.10-1.module+el8.10.0+40200+0fd0f175.src.rpm golang-bin-0:1.25.10-1.module+el8.10.0+40200+0fd0f175.aarch64.rpm golang-docs-0:1.25.10-1.module+el8.10.0+40200+0fd0f175.noarch.rpm golang-misc-0:1.25.10-1.module+el8.10.0+40200+0fd0f175.noarch.rpm golang-race-0:1.25.10-1.module+el8.10.0+40200+0fd0f175.aarch64.rpm golang-src-0:1.25.10-1.module+el8.10.0+40200+0fd0f175.noarch.rpm golang-tests-0:1.25.10-1.module+el8.10.0+40200+0fd0f175.noarch.rpm go-toolset-0:1.25.10-1.module+el8.10.0+40200+0fd0f175.aarch64.rpm