CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-39821

Critical · CVSS 9.6

golang.org/x/net/idna — Improper Input Validation / Punycode label bypass leading to privilege escalation

CVSS
9.6
nvd
EPSS
0.66%
48th pct
KEV
No
Class
oss containerizable
CWE-1289, CWE-1289

Description

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

Search profile — drives PoC discovery

Symbols ToASCIIToUnicodexn--Punycodeidnagolang.org/x/net/idna
Keywords CVE-2026-39821GO-2026-5026golang idna punycode privilege escalationToASCII ToUnicode bypassxn-- label ASCII bypass Gogolang x/net idna exploitpunycode IDN homograph bypass golangCWE-1289 golang idna
Versions: golang.org/x/net/idna prior to fix in CL 767220 / issue #78760

Affected packages

Go golang.org/x/net 0 → 0.55.0
Go stdlib 0 → 1.25.13
Go stdlib 1.26.0-0 → 1.26.6
Go stdlib 1.27.0-0 → 1.27.0-rc.3

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z