[Apollo] Advisories Statistics light light Login

RLSA-2026:22120

Security Mirrored from RHSA-2026:22120
Issued at: 2026-08-26
Updated at: 2026-08-26

Advisory content derived from Red Hat RHSA-2026:22120, © Red Hat, Inc., used under CC BY 4.0, with modifications.

Synopsis

Important: golang security update



Description

The golang packages provide the Go programming language compiler.

Security Fix(es):

* net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)

* cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy (CVE-2026-42501)

* html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content (CVE-2026-39823)

* cmd/go: golang: Go 'go bug' command: Arbitrary file overwrite via symlink attack (CVE-2026-39819)

* net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814)

* net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)

* net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)

* net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (CVE-2026-39825)

* cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction (CVE-2026-39817)

* html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping (CVE-2026-39826)

* net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows (CVE-2026-39836)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 10 aarch64 Rocky Linux 10 ppc64le Rocky Linux 10 riscv64 Rocky Linux 10 s390x Rocky Linux 10 x86_64

Fixes

2467813 2467825 2467811 2467820 2467823 2467815 2467810 2467809 2467822 2467826 2467827

CVEs

CVE-2026-33811 CVE-2026-33814 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501

Affected packages

Rocky Linux 10 riscv64 - AppStream

golang-src-0:1.26.3-4.el10_2.noarch.rpm golang-misc-0:1.26.3-4.el10_2.noarch.rpm golang-docs-0:1.26.3-4.el10_2.noarch.rpm golang-tests-0:1.26.3-4.el10_2.noarch.rpm golang-0:1.26.3-4.el10_2.src.rpm

Rocky Linux 10 s390x - AppStream

golang-src-0:1.26.3-4.el10_2.noarch.rpm golang-bin-0:1.26.3-4.el10_2.s390x.rpm golang-0:1.26.3-4.el10_2.s390x.rpm golang-misc-0:1.26.3-4.el10_2.noarch.rpm golang-docs-0:1.26.3-4.el10_2.noarch.rpm golang-tests-0:1.26.3-4.el10_2.noarch.rpm golang-0:1.26.3-4.el10_2.src.rpm golang-race-0:1.26.3-4.el10_2.s390x.rpm go-toolset-0:1.26.3-4.el10_2.s390x.rpm

Rocky Linux 10 x86_64 - AppStream

golang-src-0:1.26.3-4.el10_2.noarch.rpm go-toolset-0:1.26.3-4.el10_2.x86_64.rpm golang-0:1.26.3-4.el10_2.x86_64.rpm golang-misc-0:1.26.3-4.el10_2.noarch.rpm golang-docs-0:1.26.3-4.el10_2.noarch.rpm golang-tests-0:1.26.3-4.el10_2.noarch.rpm golang-0:1.26.3-4.el10_2.src.rpm golang-bin-0:1.26.3-4.el10_2.x86_64.rpm golang-race-0:1.26.3-4.el10_2.x86_64.rpm

Rocky Linux 10 aarch64 - AppStream

golang-race-0:1.26.3-4.el10_2.aarch64.rpm golang-src-0:1.26.3-4.el10_2.noarch.rpm go-toolset-0:1.26.3-4.el10_2.aarch64.rpm golang-bin-0:1.26.3-4.el10_2.aarch64.rpm golang-misc-0:1.26.3-4.el10_2.noarch.rpm golang-docs-0:1.26.3-4.el10_2.noarch.rpm golang-tests-0:1.26.3-4.el10_2.noarch.rpm golang-0:1.26.3-4.el10_2.src.rpm golang-0:1.26.3-4.el10_2.aarch64.rpm

Rocky Linux 10 ppc64le - AppStream

golang-bin-0:1.26.3-4.el10_2.ppc64le.rpm golang-src-0:1.26.3-4.el10_2.noarch.rpm go-toolset-0:1.26.3-4.el10_2.ppc64le.rpm golang-misc-0:1.26.3-4.el10_2.noarch.rpm golang-docs-0:1.26.3-4.el10_2.noarch.rpm golang-tests-0:1.26.3-4.el10_2.noarch.rpm golang-0:1.26.3-4.el10_2.src.rpm golang-0:1.26.3-4.el10_2.ppc64le.rpm golang-race-0:1.26.3-4.el10_2.ppc64le.rpm