RHSA-2026:37435HighCVSS 8.2

Red Hat Security Advisory: golang security, bug fix, and enhancement update

Published
July 9, 2026
Last Modified
July 17, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39822 — os: golang: Go os.Root: Symlink following vulnerability allows directory traversal

🔗 References (6)