[ALSA-2026:22112] Important: go-toolset:rhel8 security update
Type:
security
Severity:
important
Release date:
2026-09-29
Description:
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. Security Fix(es): * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) * cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy (CVE-2026-42501) * html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content (CVE-2026-39823) * cmd/go: golang: Go 'go bug' command: Arbitrary file overwrite via symlink attack (CVE-2026-39819) * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (CVE-2026-39825) * cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction (CVE-2026-39817) * html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping (CVE-2026-39826) * net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows (CVE-2026-39836) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 golang-bin-1.25.10-1.module_el8.10.0+4187+c45165c4.aarch64.rpm 0a6195f5f917e27fc46603aeeb1ddd0516ebb340101cc6e3d82d4917811604c4
aarch64 go-toolset-1.25.10-1.module_el8.10.0+4187+c45165c4.aarch64.rpm 110324dbcf03f997cd335001deae074c5803d1b33aaac0b2ef152a6e3998c49d
aarch64 golang-1.25.10-1.module_el8.10.0+4187+c45165c4.aarch64.rpm 1affa4ec36bbefa7cf5cabbe56edf6fc3d12833bb25cf741adaa7cd8668d7351
aarch64 golang-race-1.25.10-1.module_el8.10.0+4187+c45165c4.aarch64.rpm 733e1ea51c6f99c93a461bfbd47da7f8840843a576f04a0b913a7299608cbe49
aarch64 delve-1.25.2-1.module_el8.10.0+4074+24330916.aarch64.rpm 88f630e03417fb2d3eb2d58ecb082b2dc0cec1276445da41571e47d1d3fbfc26
noarch golang-tests-1.25.10-1.module_el8.10.0+4187+c45165c4.noarch.rpm 41e603de3816580c074ba52b81b9aac90a64d58a915e5747d555ec3607d96ca6
noarch golang-misc-1.25.10-1.module_el8.10.0+4187+c45165c4.noarch.rpm 6b17e36717e8284f3c19b5e532ef7ad67ce74c4e2b9f800f51ecefd2a08adde0
noarch golang-docs-1.25.10-1.module_el8.10.0+4187+c45165c4.noarch.rpm c29aa62b8b20dd63d9993d333eb775639320ed7d5bfe58bcdedffcdf530da78d
noarch golang-src-1.25.10-1.module_el8.10.0+4187+c45165c4.noarch.rpm e29e70f2e6a117a3d2cc2729dec6583e3b27b8befe39ed241e3ace5d1aa7b421
ppc64le golang-race-1.25.10-1.module_el8.10.0+4187+c45165c4.ppc64le.rpm 020a750ad1b4fcf4d7c910d8b974cbc72ba1de242c9cf276b6ab4b16b37b3d8d
ppc64le delve-1.25.2-1.module_el8.10.0+4074+24330916.ppc64le.rpm 17d4c313ef3d0be4e1327a134976fe78c5a06923d13ce8f0bc7c2c3bf4e71eab
ppc64le go-toolset-1.25.10-1.module_el8.10.0+4187+c45165c4.ppc64le.rpm 4cbcabceded74e31eee83640017ab36fae5369bfc47e3de5c44a3451953a5fa1
ppc64le golang-bin-1.25.10-1.module_el8.10.0+4187+c45165c4.ppc64le.rpm 56b5b166e268d4d0327e6f6882cca6a4be5237af1d89e44ce7dce926d49d4f2f
ppc64le golang-1.25.10-1.module_el8.10.0+4187+c45165c4.ppc64le.rpm bdeed6b629e59e625615160d98b5f0d1fdcd5f5091b861213cf281ac565a6a40
s390x golang-1.25.10-1.module_el8.10.0+4187+c45165c4.s390x.rpm 27e65b840048bdfd08e2b00319af3bead4b7824de77f1774d412e1568f02cfc7
s390x golang-race-1.25.10-1.module_el8.10.0+4187+c45165c4.s390x.rpm 56a208454e68fb67e3b32d9712f6f216259a86f9966961d40e92b61dc1442153
s390x golang-bin-1.25.10-1.module_el8.10.0+4187+c45165c4.s390x.rpm b593f24397e726083983918d41d0f97a5e3f684e5287a8fe88287e46f2b4bf34
s390x go-toolset-1.25.10-1.module_el8.10.0+4187+c45165c4.s390x.rpm e552cc1c6719856e7ce296f350d5eba9aee5f745140653edab52992d8f0d7b45
x86_64 go-toolset-1.25.10-1.module_el8.10.0+4187+c45165c4.x86_64.rpm 796c5482cd2a695719af8462d16614ecca79546454b4883834b64960779612a9
x86_64 golang-1.25.10-1.module_el8.10.0+4187+c45165c4.x86_64.rpm c63b2b499bc6584b78e9daca59155c75288ac314ac77d6700e416f414a381bd8
x86_64 delve-1.25.2-1.module_el8.10.0+4074+24330916.x86_64.rpm c977ca34ac6c92aabfc6e36e40a42dc248b1c39360b630b3d722e77ddc66e9fb
x86_64 golang-race-1.25.10-1.module_el8.10.0+4187+c45165c4.x86_64.rpm d8b73e7d32d5f31673bd80b5323f0f6aef9e560c259e97d907093a5cf15c6211
x86_64 golang-bin-1.25.10-1.module_el8.10.0+4187+c45165c4.x86_64.rpm f401fa000237b007b71f8e3bd1977291c73b3ce8a1e1fdbbf1774402a39bdc1a
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.