---
id: CVE-2026-39836
title: >-
  net: golang: Go net package: Denial of Service via NUL byte in Dial and
  LookupPort on Windows (CVE-2026-39836)
summary: >-
  A flaw was found in the `net` package of Go (golang). When running on Windows,
  the `Dial` and `LookupPort` functions can panic if they receive an input
  containing a NUL (0) byte. This can be triggered by a remote attacker
  providing a speci…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-617
vendor: Red Hat
product: Red Hat Enterprise Linux AppStream (v. 8)
affected:
  - multicluster_engine_for_kubernetes
  - openshift_api_for_data_protection
  - openshift_pipelines
  - trusted_artifact_signer
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_v_9
  - hardened_images
  - openshift_gitops 1.19
  - web_terminal 1.11
  - web_terminal 1.12
  - web_terminal 1.13
  - web_terminal 1.14
  - web_terminal 1.15
  - web_terminal 1.16
  - multicluster_engine_for_kubernetes 2.11
patched:
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_v_9
  - hardened_images
  - openshift_gitops 1.19
  - web_terminal 1.11
  - web_terminal 1.12
  - web_terminal 1.13
  - web_terminal 1.14
  - web_terminal 1.15
  - web_terminal 1.16
  - multicluster_engine_for_kubernetes 2.11
published: '2026-05-07'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:36:50+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39836.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39836.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-39836'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2467827'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-39836'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-39836'
  - url: 'https://go.dev/cl/775320'
  - url: 'https://go.dev/issue/79006'
  - url: 'https://groups.google.com/g/golang-announce/c/qcCIEXso47M'
  - url: 'https://pkg.go.dev/vuln/GO-2026-4971'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22120'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22112'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22121'
  - url: 'https://access.redhat.com/errata/RHSA-2026:23262'
  - url: 'https://access.redhat.com/errata/RHSA-2026:23264'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52857'
  - url: 'https://access.redhat.com/errata/RHSA-2026:55901'
  - url: 'https://access.redhat.com/errata/RHSA-2026:55898'
  - url: 'https://access.redhat.com/errata/RHSA-2026:55902'
  - url: 'https://access.redhat.com/errata/RHSA-2026:55903'
  - url: 'https://access.redhat.com/errata/RHSA-2026:55900'
  - url: 'https://access.redhat.com/errata/RHSA-2026:55899'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57194'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.0062
epssPercentile: 0.47398
aliases:
  - GO-2026-4971
  - BIT-golang-2026-39836
ecosystem: go
ingestedAt: '2026-08-01T19:10:58.480Z'
---

## Overview

A flaw was found in the `net` package of Go (golang). When running on Windows, the `Dial` and `LookupPort` functions can panic if they receive an input containing a NUL (0) byte. This can be triggered by a remote attacker providing a specially crafted input, leading to a denial of service (DoS) for applications using these functions.

## Vendor advisories

- **RHSA-2026:22120** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22120)
- **RHSA-2026:22112** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22112)
- **RHSA-2026:22121** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22121)
- **RHSA-2026:23262** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:23262)
- **RHSA-2026:23264** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:23264)
- **RHSA-2026:52857** · Red Hat · fixed in: Red Hat OpenShift GitOps 1.19 · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52857)
- **RHSA-2026:55901** · Red Hat · fixed in: Red Hat Web Terminal 1.11 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:55901)
- **RHSA-2026:55898** · Red Hat · fixed in: Red Hat Web Terminal 1.12 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:55898)
- **RHSA-2026:55902** · Red Hat · fixed in: Red Hat Web Terminal 1.13 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:55902)
- **RHSA-2026:55903** · Red Hat · fixed in: Red Hat Web Terminal 1.14 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:55903)
- **RHSA-2026:55900** · Red Hat · fixed in: Red Hat Web Terminal 1.15 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:55900)
- **Red Hat VEX** · Moderate · affected: Multicluster Engine for Kubernetes, OpenShift API for Data Protection, OpenShift Pipelines, Red Hat Trusted Artifact Signer · no fix planned: Multicluster Engine for Kubernetes, OpenShift API for Data Protection, OpenShift Pipelines, Red Hat Trusted Artifact Signer · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39836.json)

**net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows** — rated Moderate by Red Hat. Released 2026-05-07, updated 2026-09-21.

Affected:

- Multicluster Engine for Kubernetes
- OpenShift API for Data Protection
- OpenShift Pipelines
- Red Hat Trusted Artifact Signer

Fixed:

- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Hardened Images
- Red Hat OpenShift GitOps 1.19
- Red Hat Web Terminal 1.11
- Red Hat Web Terminal 1.12
- Red Hat Web Terminal 1.13
- Red Hat Web Terminal 1.14
- Red Hat Web Terminal 1.15
- Red Hat Web Terminal 1.16
- multicluster engine for Kubernetes 2.11

No fix planned:

- Multicluster Engine for Kubernetes
- OpenShift API for Data Protection
- OpenShift Pipelines
- Red Hat Trusted Artifact Signer

Not affected:

- Red Hat OpenShift GitOps 1.19
- Red Hat Web Terminal 1.11
- Red Hat Web Terminal 1.12
- Red Hat Web Terminal 1.13
- Red Hat Web Terminal 1.14
- Red Hat Web Terminal 1.15
- Red Hat Web Terminal 1.16
- Assisted Installer for Red Hat OpenShift Container Platform 2
- Builds for Red Hat OpenShift
- cert-manager Operator for Red Hat OpenShift

## Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:22120
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:22112
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:22121

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-39836)

Affected packages:

- `stdlib >= 1.26.0-0, < 1.26.3`

Patched in:

- `stdlib 1.26.3`

Source: https://osv.dev/vulnerability/GO-2026-4971
