{"id":"CVE-2026-39836","title":"net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows (CVE-2026-39836)","summary":"A flaw was found in the `net` package of Go (golang). When running on Windows, the `Dial` and `LookupPort` functions can panic if they receive an input containing a NUL (0) byte. This can be triggered by a remote attacker providing a speci…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-617","vendor":"Red Hat","product":"Red Hat Enterprise Linux AppStream (v. 8)","affected":["multicluster_engine_for_kubernetes","openshift_api_for_data_protection","openshift_pipelines","trusted_artifact_signer","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_v_9","hardened_images","openshift_gitops 1.19","web_terminal 1.11","web_terminal 1.12","web_terminal 1.13","web_terminal 1.14","web_terminal 1.15","web_terminal 1.16","multicluster_engine_for_kubernetes 2.11"],"patched":["enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_v_9","hardened_images","openshift_gitops 1.19","web_terminal 1.11","web_terminal 1.12","web_terminal 1.13","web_terminal 1.14","web_terminal 1.15","web_terminal 1.16","multicluster_engine_for_kubernetes 2.11"],"published":"2026-05-07","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:36:50+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39836.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39836.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-39836"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2467827"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-39836"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39836"},{"url":"https://go.dev/cl/775320"},{"url":"https://go.dev/issue/79006"},{"url":"https://groups.google.com/g/golang-announce/c/qcCIEXso47M"},{"url":"https://pkg.go.dev/vuln/GO-2026-4971"},{"url":"https://access.redhat.com/errata/RHSA-2026:22120"},{"url":"https://access.redhat.com/errata/RHSA-2026:22112"},{"url":"https://access.redhat.com/errata/RHSA-2026:22121"},{"url":"https://access.redhat.com/errata/RHSA-2026:23262"},{"url":"https://access.redhat.com/errata/RHSA-2026:23264"},{"url":"https://access.redhat.com/errata/RHSA-2026:52857"},{"url":"https://access.redhat.com/errata/RHSA-2026:55901"},{"url":"https://access.redhat.com/errata/RHSA-2026:55898"},{"url":"https://access.redhat.com/errata/RHSA-2026:55902"},{"url":"https://access.redhat.com/errata/RHSA-2026:55903"},{"url":"https://access.redhat.com/errata/RHSA-2026:55900"},{"url":"https://access.redhat.com/errata/RHSA-2026:55899"},{"url":"https://access.redhat.com/errata/RHSA-2026:57194"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00588,"epssPercentile":0.46818,"aliases":["GO-2026-4971","BIT-golang-2026-39836"],"ecosystem":"go","ingestedAt":"2026-08-01T19:10:58.480Z","slug":"CVE-2026-39836","body":"## Overview\n\nA flaw was found in the `net` package of Go (golang). When running on Windows, the `Dial` and `LookupPort` functions can panic if they receive an input containing a NUL (0) byte. This can be triggered by a remote attacker providing a specially crafted input, leading to a denial of service (DoS) for applications using these functions.\n\n## Vendor advisories\n\n- **RHSA-2026:22120** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22120)\n- **RHSA-2026:22112** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22112)\n- **RHSA-2026:22121** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22121)\n- **RHSA-2026:23262** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:23262)\n- **RHSA-2026:23264** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:23264)\n- **RHSA-2026:52857** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.19 · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52857)\n- **RHSA-2026:55901** · Red Hat · fixed in: Red Hat Web Terminal 1.11 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:55901)\n- **RHSA-2026:55898** · Red Hat · fixed in: Red Hat Web Terminal 1.12 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:55898)\n- **RHSA-2026:55902** · Red Hat · fixed in: Red Hat Web Terminal 1.13 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:55902)\n- **RHSA-2026:55903** · Red Hat · fixed in: Red Hat Web Terminal 1.14 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:55903)\n- **RHSA-2026:55900** · Red Hat · fixed in: Red Hat Web Terminal 1.15 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:55900)\n- **Red Hat VEX** · Moderate · affected: Multicluster Engine for Kubernetes, OpenShift API for Data Protection, OpenShift Pipelines, Red Hat Trusted Artifact Signer · no fix planned: Multicluster Engine for Kubernetes, OpenShift API for Data Protection, OpenShift Pipelines, Red Hat Trusted Artifact Signer · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39836.json)\n\n**net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows** — rated Moderate by Red Hat. Released 2026-05-07, updated 2026-09-21.\n\nAffected:\n\n- Multicluster Engine for Kubernetes\n- OpenShift API for Data Protection\n- OpenShift Pipelines\n- Red Hat Trusted Artifact Signer\n\nFixed:\n\n- Red Hat Enterprise Linux AppStream (v. 10)\n- Red Hat Enterprise Linux AppStream (v. 8)\n- Red Hat Enterprise Linux AppStream (v. 9)\n- Red Hat Hardened Images\n- Red Hat OpenShift GitOps 1.19\n- Red Hat Web Terminal 1.11\n- Red Hat Web Terminal 1.12\n- Red Hat Web Terminal 1.13\n- Red Hat Web Terminal 1.14\n- Red Hat Web Terminal 1.15\n- Red Hat Web Terminal 1.16\n- multicluster engine for Kubernetes 2.11\n\nNo fix planned:\n\n- Multicluster Engine for Kubernetes\n- OpenShift API for Data Protection\n- OpenShift Pipelines\n- Red Hat Trusted Artifact Signer\n\nNot affected:\n\n- Red Hat OpenShift GitOps 1.19\n- Red Hat Web Terminal 1.11\n- Red Hat Web Terminal 1.12\n- Red Hat Web Terminal 1.13\n- Red Hat Web Terminal 1.14\n- Red Hat Web Terminal 1.15\n- Red Hat Web Terminal 1.16\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Builds for Red Hat OpenShift\n- cert-manager Operator for Red Hat OpenShift\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:22120\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:22112\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:22121\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-39836)\n\nAffected packages:\n\n- `stdlib >= 1.26.0-0, < 1.26.3`\n\nPatched in:\n\n- `stdlib 1.26.3`\n\nSource: https://osv.dev/vulnerability/GO-2026-4971","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":208951,"id":"CVE-2026-39836","ts":1790062298443,"field":"cvss","old":null,"new":"7.5"},{"seq":208950,"id":"CVE-2026-39836","ts":1790062298443,"field":"severity","old":"none","new":"high"}]}