Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CVE-2026-56859 (GCVE-0-2026-56859)
Vulnerability from cvelistv5 – Published: 2026-08-13 21:58 – Updated: 2026-08-14 15:21- CWE-770 - Allocation of Resources Without Limits or Throttling
| Vendor | Product | Version | |
|---|---|---|---|
| Go standard library | encoding/xml |
Affected:
0 , < 1.25.13
(semver)
Affected: 1.26.0-0 , < 1.26.6 (semver) Affected: 1.27.0-0 , < 1.27.0-rc.3 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-56859",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-14T15:21:09.615961Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-770",
"description": "CWE-770 Allocation of Resources Without Limits or Throttling",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-14T15:21:46.218Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://pkg.go.dev",
"defaultStatus": "unaffected",
"packageName": "encoding/xml",
"product": "encoding/xml",
"programRoutines": [
{
"name": "Decoder.push"
},
{
"name": "Decoder.pop"
},
{
"name": "Decoder.RawToken"
},
{
"name": "Decoder.unmarshalPath"
},
{
"name": "Decoder.unmarshal"
},
{
"name": "Decoder.Decode"
},
{
"name": "Decoder.DecodeElement"
},
{
"name": "Decoder.Skip"
},
{
"name": "Decoder.Token"
},
{
"name": "Unmarshal"
}
],
"vendor": "Go standard library",
"versions": [
{
"lessThan": "1.25.13",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "1.26.6",
"status": "affected",
"version": "1.26.0-0",
"versionType": "semver"
},
{
"lessThan": "1.27.0-rc.3",
"status": "affected",
"version": "1.27.0-0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-770: Allocation of Resources Without Limits or Throttling",
"lang": "en"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-13T21:58:52.959Z",
"orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc",
"shortName": "Go"
},
"references": [
{
"url": "https://go.dev/issue/80481"
},
{
"url": "https://go.dev/cl/803320"
},
{
"url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
},
{
"url": "https://pkg.go.dev/vuln/GO-2026-6088"
}
],
"title": "Add recursion depth guard during decode in encoding/xml"
}
},
"cveMetadata": {
"assignerOrgId": "1bb62c36-49e3-4200-9d77-64a1400537cc",
"assignerShortName": "Go",
"cveId": "CVE-2026-56859",
"datePublished": "2026-08-13T21:58:52.959Z",
"dateReserved": "2026-06-23T15:10:49.353Z",
"dateUpdated": "2026-08-14T15:21:46.218Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"vulnerability-lookup:meta": {
"epss": {
"cve": "CVE-2026-56859",
"date": "2026-10-03",
"epss": "0.00568",
"percentile": "0.45104"
},
"redhat_vex": {
"aggregate_severity": "Important",
"current_release_date": "2026-10-03T15:48:47+00:00",
"cve": "CVE-2026-56859",
"id": "CVE-2026-56859",
"initial_release_date": "2026-08-13T21:58:52.959000+00:00",
"product_status:fixed": "6850",
"product_status:known_affected": "248",
"product_status:known_not_affected": "3466",
"source": "Red Hat CSAF VEX",
"status": "final",
"title": "encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue",
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56859.json",
"version": "3"
},
"vulnrichment": {
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-56859",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-14T15:21:09.615961Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-770",
"description": "CWE-770 Allocation of Resources Without Limits or Throttling",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-14T15:21:41.531Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://pkg.go.dev",
"defaultStatus": "unaffected",
"packageName": "encoding/xml",
"product": "encoding/xml",
"programRoutines": [
{
"name": "Decoder.push"
},
{
"name": "Decoder.pop"
},
{
"name": "Decoder.RawToken"
},
{
"name": "Decoder.unmarshalPath"
},
{
"name": "Decoder.unmarshal"
},
{
"name": "Decoder.Decode"
},
{
"name": "Decoder.DecodeElement"
},
{
"name": "Decoder.Skip"
},
{
"name": "Decoder.Token"
},
{
"name": "Unmarshal"
}
],
"vendor": "Go standard library",
"versions": [
{
"lessThan": "1.25.13",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "1.26.6",
"status": "affected",
"version": "1.26.0-0",
"versionType": "semver"
},
{
"lessThan": "1.27.0-rc.3",
"status": "affected",
"version": "1.27.0-0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-770: Allocation of Resources Without Limits or Throttling",
"lang": "en"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-13T21:58:52.959Z",
"orgId": "1bb62c36-49e3-4200-9d77-64a1400537cc",
"shortName": "Go"
},
"references": [
{
"url": "https://go.dev/issue/80481"
},
{
"url": "https://go.dev/cl/803320"
},
{
"url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
},
{
"url": "https://pkg.go.dev/vuln/GO-2026-6088"
}
],
"title": "Add recursion depth guard during decode in encoding/xml"
}
},
"cveMetadata": {
"assignerOrgId": "1bb62c36-49e3-4200-9d77-64a1400537cc",
"assignerShortName": "Go",
"cveId": "CVE-2026-56859",
"datePublished": "2026-08-13T21:58:52.959Z",
"dateReserved": "2026-06-23T15:10:49.353Z",
"dateUpdated": "2026-08-14T15:21:46.218Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
}
}
ALSA-2026:60304
Vulnerability from osv_almalinux – Published: 2026-08-26 00:00 – Updated: 2026-08-27 08:10 – Source websiteThe golang packages provide the Go programming language compiler.
Security Fix(es):
- encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
- net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
- net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
- html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
- crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
- encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
Bug Fix(es) and Enhancement(s):
- Go 1.26 -- maxThreads limit hit in CGO threads blocked on RAND_bytes in FIPS mode (JIRA:AlmaLinux-215845)
- Update Go to version 1.26.7+1 [almalinux-9.8.z] (JIRA:AlmaLinux-246425)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
{
"affected": [
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "go-toolset"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.el9_8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "golang"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.el9_8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "golang-bin"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.el9_8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "golang-docs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.el9_8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "golang-misc"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.el9_8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "golang-race"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.el9_8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "golang-src"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.el9_8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "golang-tests"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.el9_8"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"details": "The golang packages provide the Go programming language compiler. \n\nSecurity Fix(es): \n\n * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)\n * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)\n * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)\n * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)\n * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)\n * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)\n\n\nBug Fix(es) and Enhancement(s): \n\n * Go 1.26 -- maxThreads limit hit in CGO threads blocked on RAND_bytes in FIPS mode (JIRA:AlmaLinux-215845)\n * Update Go to version 1.26.7+1 [almalinux-9.8.z] (JIRA:AlmaLinux-246425)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n",
"id": "ALSA-2026:60304",
"modified": "2026-08-27T08:10:45Z",
"published": "2026-08-26T00:00:00Z",
"references": [
{
"type": "ADVISORY",
"url": "https://access.redhat.com/errata/RHSA-2026:60304"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-33818"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56853"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56858"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56859"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56860"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56862"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515815"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515820"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515827"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515838"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515839"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515840"
},
{
"type": "ADVISORY",
"url": "https://errata.almalinux.org/9/ALSA-2026-60304.html"
}
],
"related": [
"CVE-2026-33818",
"CVE-2026-56860",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56862",
"CVE-2026-56859"
],
"summary": "Important: golang security, bug fix, and enhancement update"
}
ALSA-2026:60305
Vulnerability from osv_almalinux – Published: 2026-08-26 00:00 – Updated: 2026-08-27 08:19 – Source websiteGo Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.
Security Fix(es):
- encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
- net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
- net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
- html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
- crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
- encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
Bug Fix(es) and Enhancement(s):
- Update Go to version 1.26.7+1 [almalinux-8.10.z] (JIRA:AlmaLinux-246426)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "delve"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.1-1.module_el8.10.0+4223+bd807c2e"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "go-toolset"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.module_el8.10.0+4264+117c8fc2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "golang"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.module_el8.10.0+4264+117c8fc2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "golang-bin"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.module_el8.10.0+4264+117c8fc2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "golang-docs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.module_el8.10.0+4264+117c8fc2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "golang-misc"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.module_el8.10.0+4264+117c8fc2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "golang-race"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.module_el8.10.0+4264+117c8fc2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "golang-src"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.module_el8.10.0+4264+117c8fc2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "golang-tests"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.module_el8.10.0+4264+117c8fc2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"details": "Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. \n\nSecurity Fix(es): \n\n * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)\n * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)\n * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)\n * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)\n * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)\n * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)\n\n\nBug Fix(es) and Enhancement(s): \n\n * Update Go to version 1.26.7+1 [almalinux-8.10.z] (JIRA:AlmaLinux-246426)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n",
"id": "ALSA-2026:60305",
"modified": "2026-08-27T08:19:15Z",
"published": "2026-08-26T00:00:00Z",
"references": [
{
"type": "ADVISORY",
"url": "https://access.redhat.com/errata/RHSA-2026:60305"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-33818"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56853"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56858"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56859"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56860"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56862"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515815"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515820"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515827"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515838"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515839"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515840"
},
{
"type": "ADVISORY",
"url": "https://errata.almalinux.org/8/ALSA-2026-60305.html"
}
],
"related": [
"CVE-2026-33818",
"CVE-2026-56860",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56862",
"CVE-2026-56859"
],
"summary": "Important: go-toolset:rhel8 security, bug fix, and enhancement update"
}
ALSA-2026:60306
Vulnerability from osv_almalinux – Published: 2026-08-26 00:00 – Updated: 2026-08-27 08:19 – Source websiteThe golang packages provide the Go programming language compiler.
Security Fix(es):
- encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
- net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
- net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
- html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
- crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
- encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
Bug Fix(es) and Enhancement(s):
- Update Go to version 1.26.7+1 [almalinux-10.2.z] (JIRA:AlmaLinux-246423)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "AlmaLinux:10",
"name": "go-toolset"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.el10_2.alma.1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:10",
"name": "golang"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.el10_2.alma.1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:10",
"name": "golang-bin"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.el10_2.alma.1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:10",
"name": "golang-docs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.el10_2.alma.1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:10",
"name": "golang-misc"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.el10_2.alma.1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:10",
"name": "golang-race"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.el10_2.alma.1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:10",
"name": "golang-src"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.el10_2.alma.1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:10",
"name": "golang-tests"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.26.7-1.el10_2.alma.1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"details": "The golang packages provide the Go programming language compiler. \n\nSecurity Fix(es): \n\n * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)\n * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)\n * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)\n * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)\n * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)\n * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)\n\n\nBug Fix(es) and Enhancement(s): \n\n * Update Go to version 1.26.7+1 [almalinux-10.2.z] (JIRA:AlmaLinux-246423)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n",
"id": "ALSA-2026:60306",
"modified": "2026-08-27T08:19:16Z",
"published": "2026-08-26T00:00:00Z",
"references": [
{
"type": "ADVISORY",
"url": "https://access.redhat.com/errata/RHSA-2026:60306"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-33818"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56853"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56858"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56859"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56860"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56862"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515815"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515820"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515827"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515838"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515839"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515840"
},
{
"type": "ADVISORY",
"url": "https://errata.almalinux.org/10/ALSA-2026-60306.html"
}
],
"related": [
"CVE-2026-33818",
"CVE-2026-56860",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56862",
"CVE-2026-56859"
],
"summary": "Important: golang security, bug fix, and enhancement update"
}
ALSA-2026:62406
Vulnerability from osv_almalinux – Published: 2026-09-02 00:00 – Updated: 2026-09-23 16:49 – Source websiteGrafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.
Security Fix(es):
- net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
- net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)
- encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
- net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
- net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
- html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
- crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
- encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.2.6-23.el9_8.3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grafana-selinux"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.2.6-23.el9_8.3"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"details": "Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB \u0026 OpenTSDB. \n\nSecurity Fix(es): \n\n * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)\n * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)\n * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)\n * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)\n * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)\n * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)\n * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)\n * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n",
"id": "ALSA-2026:62406",
"modified": "2026-09-23T16:49:47Z",
"published": "2026-09-02T00:00:00Z",
"references": [
{
"type": "ADVISORY",
"url": "https://access.redhat.com/errata/RHSA-2026:62406"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-33818"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-39820"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-42499"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56853"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56858"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56859"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56860"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56862"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2467809"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2467820"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515815"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515820"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515827"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515838"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515839"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515840"
},
{
"type": "ADVISORY",
"url": "https://errata.almalinux.org/9/ALSA-2026-62406.html"
},
{
"type": "REPORT",
"url": "https://www.redhat.com/security/data/cve/CVE-2026-42504.html"
}
],
"related": [
"CVE-2026-42499",
"CVE-2026-39820",
"CVE-2026-33818",
"CVE-2026-56860",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56862",
"CVE-2026-56859"
],
"summary": "Important: grafana security update"
}
ALSA-2026:62407
Vulnerability from osv_almalinux – Published: 2026-09-02 00:00 – Updated: 2026-09-23 18:11 – Source websiteGrafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.
Security Fix(es):
- net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
- net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)
- encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
- net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
- net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
- html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
- crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
- encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "9.2.10-33.el8_10"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "grafana-selinux"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "9.2.10-33.el8_10"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"details": "Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB \u0026 OpenTSDB. \n\nSecurity Fix(es): \n\n * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)\n * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)\n * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)\n * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)\n * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)\n * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)\n * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)\n * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n",
"id": "ALSA-2026:62407",
"modified": "2026-09-23T18:11:14Z",
"published": "2026-09-02T00:00:00Z",
"references": [
{
"type": "ADVISORY",
"url": "https://access.redhat.com/errata/RHSA-2026:62407"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-33818"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-39820"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-42499"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56853"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56858"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56859"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56860"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56862"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2467809"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2467820"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515815"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515820"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515827"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515838"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515839"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515840"
},
{
"type": "ADVISORY",
"url": "https://errata.almalinux.org/8/ALSA-2026-62407.html"
},
{
"type": "REPORT",
"url": "https://www.redhat.com/security/data/cve/CVE-2026-42504.html"
}
],
"related": [
"CVE-2026-42499",
"CVE-2026-39820",
"CVE-2026-33818",
"CVE-2026-56860",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56862",
"CVE-2026-56859"
],
"summary": "Important: grafana security update"
}
ALSA-2026:62631
Vulnerability from osv_almalinux – Published: 2026-09-02 00:00 – Updated: 2026-09-03 08:39 – Source websiteHTTP reverse proxy, backed by IPP-over-USB connection to device. It enables
driverless support for USB devices capable of using IPP-over-USB protocol.
Security Fix(es):
- mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
- encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
- net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
- net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
- crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
- encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "AlmaLinux:10",
"name": "ipp-usb"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.9.27-7.el10_2.3"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"details": "HTTP reverse proxy, backed by IPP-over-USB connection to device. It enables \ndriverless support for USB devices capable of using IPP-over-USB protocol. \n\nSecurity Fix(es): \n\n * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)\n * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)\n * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)\n * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)\n * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)\n * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n",
"id": "ALSA-2026:62631",
"modified": "2026-09-03T08:39:24Z",
"published": "2026-09-02T00:00:00Z",
"references": [
{
"type": "ADVISORY",
"url": "https://access.redhat.com/errata/RHSA-2026:62631"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-33818"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-42504"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56853"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56859"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56860"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56862"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2484204"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515815"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515820"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515827"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515839"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515840"
},
{
"type": "ADVISORY",
"url": "https://errata.almalinux.org/10/ALSA-2026-62631.html"
}
],
"related": [
"CVE-2026-42504",
"CVE-2026-33818",
"CVE-2026-56860",
"CVE-2026-56853",
"CVE-2026-56862",
"CVE-2026-56859"
],
"summary": "Important: golang-github-openprinting-ipp-usb security update"
}
ALSA-2026:63022
Vulnerability from osv_almalinux – Published: 2026-09-03 00:00 – Updated: 2026-09-23 23:57 – Source websiteGrafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.
Security Fix(es):
- net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
- net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)
- encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
- net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
- net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
- html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
- crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
- encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
| URL | Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "AlmaLinux:10",
"name": "grafana"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.2.6-28.el10_2.5"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:10",
"name": "grafana-selinux"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.2.6-28.el10_2.5"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"details": "Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB \u0026 OpenTSDB. \n\nSecurity Fix(es): \n\n * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)\n * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)\n * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)\n * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)\n * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)\n * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)\n * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)\n * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n",
"id": "ALSA-2026:63022",
"modified": "2026-09-23T23:57:03Z",
"published": "2026-09-03T00:00:00Z",
"references": [
{
"type": "ADVISORY",
"url": "https://access.redhat.com/errata/RHSA-2026:63022"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-33818"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-39820"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-42499"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56853"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56858"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56859"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56860"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56862"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2467809"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2467820"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515815"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515820"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515827"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515838"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515839"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515840"
},
{
"type": "ADVISORY",
"url": "https://errata.almalinux.org/10/ALSA-2026-63022.html"
},
{
"type": "REPORT",
"url": "https://www.redhat.com/security/data/cve/CVE-2026-42504.html"
}
],
"related": [
"CVE-2026-42499",
"CVE-2026-39820",
"CVE-2026-33818",
"CVE-2026-56860",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56862",
"CVE-2026-56859"
],
"summary": "Important: grafana security update"
}
ALSA-2026:63163
Vulnerability from osv_almalinux – Published: 2026-09-03 00:00 – Updated: 2026-09-29 13:06 – Source websiteThe container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.
Security Fix(es):
- net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
- encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
- net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
- net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
- html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
- crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
- encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "aardvark-dns"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:1.10.1-2.module_el8.10.0+3909+6e1c1eb7"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "aardvark-dns"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:1.10.1-2.module_el8.10.0+4023+db236c53"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "aardvark-dns"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:1.10.1-2.module_el8.10.0+4047+545787c4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "aardvark-dns"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:1.10.1-2.module_el8.10.0+3901+4b80ecd7"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "buildah"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:1.33.14-6.module_el8.10.0+4269+94686149"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "buildah-tests"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:1.33.14-6.module_el8.10.0+4269+94686149"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "cockpit-podman"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "84.1-1.module_el8.10.0+4102+6c76e544"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "conmon"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3:2.1.10-1.module_el8.10.0+3970+8445edf6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "conmon"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3:2.1.10-1.module_el8.10.0+3845+87b84552"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "container-selinux"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:2.229.0-3.module_el8.10.0+4213+0493256b"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "containernetworking-plugins"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:1.4.0-10.module_el8.10.0+4269+94686149"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "containers-common"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:1-82.module_el8.10.0+4016+efd18bf8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "containers-common"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:1-82.module_el8.10.0+4068+0e21408f"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "containers-common"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:1-82.module_el8.10.0+4120+03ad4b47"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "containers-common"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:1-82.module_el8.10.0+4089+ce72bbbe"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "crit"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+4047+545787c4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "crit"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+3901+4b80ecd7"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "crit"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+4120+03ad4b47"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "crit"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+3845+87b84552"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "criu"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+4120+03ad4b47"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "criu"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+3876+e55593a8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "criu"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+3845+87b84552"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "criu"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+3970+8445edf6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "criu-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+4016+efd18bf8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "criu-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+4082+f7f0c95e"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "criu-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+4089+ce72bbbe"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "criu-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+4068+0e21408f"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "criu-libs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+4068+0e21408f"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "criu-libs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+3970+8445edf6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "criu-libs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+3909+6e1c1eb7"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "criu-libs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+4082+f7f0c95e"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "crun"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.14.3-4.module_el8.10.0+4269+94686149"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "fuse-overlayfs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.13-1.module_el8.10.0+3970+8445edf6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "fuse-overlayfs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.13-1.module_el8.10.0+4082+f7f0c95e"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "fuse-overlayfs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.13-1.module_el8.10.0+4068+0e21408f"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "fuse-overlayfs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.13-1.module_el8.10.0+3909+6e1c1eb7"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libslirp"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.4.0-2.module_el8.10.0+4016+efd18bf8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libslirp"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.4.0-2.module_el8.10.0+4068+0e21408f"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libslirp"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.4.0-2.module_el8.10.0+4090+91932338"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libslirp"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.4.0-2.module_el8.10.0+4120+03ad4b47"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libslirp-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.4.0-2.module_el8.10.0+4102+6c76e544"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libslirp-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.4.0-2.module_el8.10.0+4068+0e21408f"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libslirp-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.4.0-2.module_el8.10.0+3970+8445edf6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libslirp-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.4.0-2.module_el8.10.0+4082+f7f0c95e"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "netavark"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:1.10.3-1.module_el8.10.0+4023+db236c53"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "netavark"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:1.10.3-1.module_el8.10.0+3926+f12484f5"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "netavark"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:1.10.3-1.module_el8.10.0+4082+f7f0c95e"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "netavark"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:1.10.3-1.module_el8.10.0+4047+545787c4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "oci-seccomp-bpf-hook"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.10-3.module_el8.10.0+4269+94686149"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "podman"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4:4.9.4-37.module_el8.10.0+4269+94686149"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "podman-catatonit"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4:4.9.4-37.module_el8.10.0+4269+94686149"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "podman-docker"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4:4.9.4-37.module_el8.10.0+4269+94686149"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "podman-gvproxy"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4:4.9.4-37.module_el8.10.0+4269+94686149"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "podman-plugins"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4:4.9.4-37.module_el8.10.0+4269+94686149"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "podman-remote"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4:4.9.4-37.module_el8.10.0+4269+94686149"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "podman-tests"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4:4.9.4-37.module_el8.10.0+4269+94686149"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "python3-criu"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+3858+6ad51f9f"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "python3-criu"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+3901+4b80ecd7"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "python3-criu"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+4047+545787c4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "python3-criu"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.18-5.module_el8.10.0+4120+03ad4b47"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "python3-podman"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.9.0-3.module_el8.10.0+4016+efd18bf8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "runc"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4:1.2.9-6.module_el8.10.0+4269+94686149"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "skopeo"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:1.14.6-4.module_el8.10.0+4269+94686149"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "skopeo-tests"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2:1.14.6-4.module_el8.10.0+4269+94686149"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "slirp4netns"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.3-1.module_el8.10.0+4047+545787c4"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "slirp4netns"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.3-1.module_el8.10.0+4023+db236c53"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "slirp4netns"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.3-1.module_el8.10.0+3901+4b80ecd7"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "slirp4netns"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.3-1.module_el8.10.0+4082+f7f0c95e"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "toolbox"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.0.99.5.1-1.module_el8.10.0+4120+03ad4b47"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "toolbox-tests"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.0.99.5.1-1.module_el8.10.0+4120+03ad4b47"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "udica"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.2.6-21.module_el8.10.0+4068+0e21408f"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"details": "The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. \n\nSecurity Fix(es): \n\n * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)\n * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)\n * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)\n * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)\n * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)\n * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)\n * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n",
"id": "ALSA-2026:63163",
"modified": "2026-09-29T13:06:48Z",
"published": "2026-09-03T00:00:00Z",
"references": [
{
"type": "ADVISORY",
"url": "https://access.redhat.com/errata/RHSA-2026:63163"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-33818"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-42499"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56853"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56858"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56859"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56860"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56862"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2467809"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515815"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515820"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515827"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515838"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515839"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515840"
},
{
"type": "ADVISORY",
"url": "https://errata.almalinux.org/8/ALSA-2026-63163.html"
}
],
"related": [
"CVE-2026-42499",
"CVE-2026-33818",
"CVE-2026-56860",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56862",
"CVE-2026-56859"
],
"summary": "Important: container-tools:rhel8 security update"
}
ALSA-2026:65116
Vulnerability from osv_almalinux – Published: 2026-09-08 00:00 – Updated: 2026-09-09 13:34 – Source websiteCollector with the supported components for a AlmaLinux build of OpenTelemetry
Security Fix(es):
- net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
- net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)
- mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
- github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)
- encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
- net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
- net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
- html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
- crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
- encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "AlmaLinux:10",
"name": "opentelemetry-collector"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.152.1-2.el10_2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"details": "Collector with the supported components for a AlmaLinux build of OpenTelemetry \n\nSecurity Fix(es): \n\n * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)\n * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)\n * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)\n * github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)\n * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)\n * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)\n * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)\n * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)\n * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)\n * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n",
"id": "ALSA-2026:65116",
"modified": "2026-09-09T13:34:18Z",
"published": "2026-09-08T00:00:00Z",
"references": [
{
"type": "ADVISORY",
"url": "https://access.redhat.com/errata/RHSA-2026:65116"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-33818"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-39820"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-41178"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-42499"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-42504"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56853"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56858"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56859"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56860"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56862"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2467809"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2467820"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2484204"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2484830"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515815"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515820"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515827"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515838"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515839"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515840"
},
{
"type": "ADVISORY",
"url": "https://errata.almalinux.org/10/ALSA-2026-65116.html"
}
],
"related": [
"CVE-2026-42499",
"CVE-2026-39820",
"CVE-2026-42504",
"CVE-2026-41178",
"CVE-2026-33818",
"CVE-2026-56860",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56862",
"CVE-2026-56859"
],
"summary": "Important: opentelemetry-collector security update"
}
ALSA-2026:65117
Vulnerability from osv_almalinux – Published: 2026-09-08 00:00 – Updated: 2026-09-09 13:34 – Source websiteCollector with the supported components for a AlmaLinux build of OpenTelemetry
Security Fix(es):
- net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
- net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)
- mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
- github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)
- encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
- net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
- net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
- html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
- crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
- encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
| URL | Type | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"affected": [
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "opentelemetry-collector"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.152.1-2.el9_8"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"details": "Collector with the supported components for a AlmaLinux build of OpenTelemetry \n\nSecurity Fix(es): \n\n * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)\n * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)\n * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)\n * github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)\n * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)\n * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)\n * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)\n * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)\n * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)\n * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n",
"id": "ALSA-2026:65117",
"modified": "2026-09-09T13:34:15Z",
"published": "2026-09-08T00:00:00Z",
"references": [
{
"type": "ADVISORY",
"url": "https://access.redhat.com/errata/RHSA-2026:65117"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-33818"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-39820"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-41178"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-42499"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-42504"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56853"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56858"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56859"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56860"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2026-56862"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2467809"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2467820"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2484204"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2484830"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515815"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515820"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515827"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515838"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515839"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2515840"
},
{
"type": "ADVISORY",
"url": "https://errata.almalinux.org/9/ALSA-2026-65117.html"
}
],
"related": [
"CVE-2026-42499",
"CVE-2026-39820",
"CVE-2026-42504",
"CVE-2026-41178",
"CVE-2026-33818",
"CVE-2026-56860",
"CVE-2026-56853",
"CVE-2026-56858",
"CVE-2026-56862",
"CVE-2026-56859"
],
"summary": "Important: opentelemetry-collector security update"
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.