CVE-2026-39821
Critical · CVSS 9.6golang.org/x/net/idna — Improper Input Validation / Punycode label bypass leading to privilege escalation
- CVSS
- 9.6
- nvd
- EPSS
- 0.66%
- 48th pct
- KEV
- No
- Class
- oss containerizable
- CWE-1289, CWE-1289
Description
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
Search profile — drives PoC discovery
Affected packages
| Go | golang.org/x/net | 0 → 0.55.0 |
| Go | stdlib | 0 → 1.25.13 |
| Go | stdlib | 1.26.0-0 → 1.26.6 |
| Go | stdlib | 1.27.0-0 → 1.27.0-rc.3 |
References
- https://go.dev/cl/767220
- https://go.dev/issue/78760
- https://groups.google.com/g/golang-announce/c/94pEornpRlI
- https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
- https://pkg.go.dev/vuln/GO-2026-5026
- https://access.redhat.com/errata/RHSA-2026:23262
- https://access.redhat.com/errata/RHSA-2026:23264
- https://access.redhat.com/errata/RHSA-2026:26546
- https://access.redhat.com/errata/RHSA-2026:26547
- https://access.redhat.com/errata/RHSA-2026:30650
- https://access.redhat.com/errata/RHSA-2026:30651
- https://access.redhat.com/errata/RHSA-2026:30853
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z