[Apollo] Advisories Statistics light light Login

RLSA-2026:22121

Security Mirrored from RHSA-2026:22121
Issued at: 2026-08-26
Updated at: 2026-08-26

Advisory content derived from Red Hat RHSA-2026:22121, © Red Hat, Inc., used under CC BY 4.0, with modifications.

Synopsis

Important: golang security update



Description

The golang packages provide the Go programming language compiler.

Security Fix(es):

* net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)

* cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy (CVE-2026-42501)

* html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content (CVE-2026-39823)

* cmd/go: golang: Go 'go bug' command: Arbitrary file overwrite via symlink attack (CVE-2026-39819)

* net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814)

* net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)

* net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)

* net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (CVE-2026-39825)

* cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction (CVE-2026-39817)

* html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping (CVE-2026-39826)

* net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows (CVE-2026-39836)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 9 aarch64 Rocky Linux 9 ppc64le Rocky Linux 9 s390x Rocky Linux 9 x86_64

Fixes

2467809 2467810 2467811 2467813 2467815 2467820 2467822 2467823 2467825 2467826 2467827

CVEs

CVE-2026-33811 CVE-2026-33814 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501

Affected packages

Rocky Linux 9 aarch64 - AppStream

golang-0:1.26.3-1.el9_8.aarch64.rpm golang-0:1.26.3-1.el9_8.src.rpm golang-bin-0:1.26.3-1.el9_8.aarch64.rpm golang-docs-0:1.26.3-1.el9_8.noarch.rpm golang-misc-0:1.26.3-1.el9_8.noarch.rpm golang-race-0:1.26.3-1.el9_8.aarch64.rpm golang-src-0:1.26.3-1.el9_8.noarch.rpm golang-tests-0:1.26.3-1.el9_8.noarch.rpm go-toolset-0:1.26.3-1.el9_8.aarch64.rpm

Rocky Linux 9 ppc64le - AppStream

golang-0:1.26.3-1.el9_8.ppc64le.rpm golang-0:1.26.3-1.el9_8.src.rpm golang-bin-0:1.26.3-1.el9_8.ppc64le.rpm golang-docs-0:1.26.3-1.el9_8.noarch.rpm golang-misc-0:1.26.3-1.el9_8.noarch.rpm golang-race-0:1.26.3-1.el9_8.ppc64le.rpm golang-src-0:1.26.3-1.el9_8.noarch.rpm golang-tests-0:1.26.3-1.el9_8.noarch.rpm go-toolset-0:1.26.3-1.el9_8.ppc64le.rpm

Rocky Linux 9 s390x - AppStream

golang-0:1.26.3-1.el9_8.s390x.rpm golang-0:1.26.3-1.el9_8.src.rpm golang-bin-0:1.26.3-1.el9_8.s390x.rpm golang-docs-0:1.26.3-1.el9_8.noarch.rpm golang-misc-0:1.26.3-1.el9_8.noarch.rpm golang-race-0:1.26.3-1.el9_8.s390x.rpm golang-src-0:1.26.3-1.el9_8.noarch.rpm golang-tests-0:1.26.3-1.el9_8.noarch.rpm go-toolset-0:1.26.3-1.el9_8.s390x.rpm

Rocky Linux 9 x86_64 - AppStream

golang-0:1.26.3-1.el9_8.src.rpm golang-0:1.26.3-1.el9_8.x86_64.rpm golang-bin-0:1.26.3-1.el9_8.x86_64.rpm golang-docs-0:1.26.3-1.el9_8.noarch.rpm golang-misc-0:1.26.3-1.el9_8.noarch.rpm golang-race-0:1.26.3-1.el9_8.x86_64.rpm golang-src-0:1.26.3-1.el9_8.noarch.rpm golang-tests-0:1.26.3-1.el9_8.noarch.rpm go-toolset-0:1.26.3-1.el9_8.x86_64.rpm