Overview
A flaw was found in the net/textproto package in Golang. When functions in this package return errors, they include their input as part of the error message. An attacker could exploit this by injecting misleading content into these error messages, which are then printed or logged. This could lead to confusion or misinterpretation of critical system information.
Vendor advisories
- RHSA-2026:49702 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-08-03 · advisory
- RHSA-2026:29980 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-06-25 · advisory
- RHSA-2026:38995 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-07-13 · advisory
- RHSA-2026:61253 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-08-31 · advisory
- RHSA-2026:57649 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-08-20 · advisory
- RHSA-2026:49712 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-08-03 · advisory
- RHSA-2026:29981 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-06-25 · advisory
- RHSA-2026:23262 · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-04 · advisory
- RHSA-2026:23264 · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-04 · advisory
- RHSA-2026:50205 · Red Hat · fixed in: Red Hat OpenShift distributed tracing 3.10.2 · released 2026-08-04 · advisory
- RHSA-2026:33612 · Red Hat · fixed in: Red Hat OpenShift distributed tracing 3.10.2 · released 2026-06-30 · advisory
- Red Hat VEX · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, cert-manager Operator for Red Hat OpenShift, Compliance Operator, Confidential Compute Attestation, Cryostat 4, … · no fix planned: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, cert-manager Operator for Red Hat OpenShift, Compliance Operator, … · updated 2026-09-08 · vex
net/textproto: golang: Golang net/textproto: Misleading error messages via input injection — rated Moderate by Red Hat. Released 2026-06-02, updated 2026-09-08.
Affected:
- Assisted Installer for Red Hat OpenShift Container Platform 2
- Builds for Red Hat OpenShift
- cert-manager Operator for Red Hat OpenShift
- Compliance Operator
- Confidential Compute Attestation
- Cryostat 4
- Deployment Validation Operator
- External Secrets Operator for Red Hat OpenShift
- Fence Agents Remediation Operator
- File Integrity Operator
- Gatekeeper 3
- Logging Subsystem for Red Hat OpenShift
- Logical Volume Manager Storage
- Machine Deletion Remediation Operator
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- Multiarch Tuning Operator
- Multicluster Engine for Kubernetes
- Multicluster Global Hub
- Network Observability Operator
- Node HealthCheck Operator
- OpenShift API for Data Protection
- OpenShift Developer Tools and Services
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Serverless
- OpenShift Service Mesh 2
- OpenShift Service Mesh 3
- OpenShift Source-to-Image (S2I)
- Power monitoring for Red Hat OpenShift
- Red Hat 3scale API Management Platform 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat Ansible Automation Platform 2
- Red Hat build of Apicurio Registry 2
- Red Hat Ceph Storage 5
- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9
- Red Hat Certification Program for Red Hat Enterprise Linux 9
Fixed:
- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux AppStream E4S (v.9.2)
- Red Hat Enterprise Linux AppStream E4S (v.9.4)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Hardened Images
- Red Hat OpenShift distributed tracing 3.10.2
- multicluster engine for Kubernetes 2.11
No fix planned:
- Assisted Installer for Red Hat OpenShift Container Platform 2
- Builds for Red Hat OpenShift
- cert-manager Operator for Red Hat OpenShift
- Compliance Operator
- Confidential Compute Attestation
- Cryostat 4
- Deployment Validation Operator
- External Secrets Operator for Red Hat OpenShift
- Fence Agents Remediation Operator
- File Integrity Operator
- Gatekeeper 3
- Logging Subsystem for Red Hat OpenShift
- Logical Volume Manager Storage
- Machine Deletion Remediation Operator
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- Multiarch Tuning Operator
- Multicluster Engine for Kubernetes
- Multicluster Global Hub
- Network Observability Operator
- Node HealthCheck Operator
- OpenShift Developer Tools and Services
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Serverless
- OpenShift Service Mesh 2
- OpenShift Service Mesh 3
- OpenShift Source-to-Image (S2I)
- Power monitoring for Red Hat OpenShift
- Red Hat 3scale API Management Platform 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat Ansible Automation Platform 2
- Red Hat build of Apicurio Registry 2
- Red Hat Ceph Storage 5
- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9
- Red Hat Certification Program for Red Hat Enterprise Linux 9
- Red Hat Connectivity Link 1
Not affected:
- Red Hat OpenShift distributed tracing 3.10.2
- multicluster engine for Kubernetes 2.11
Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:49702
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:29980
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:38995
Workarounds / mitigations:
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Package advisory (CVE-2026-42507)
Affected packages:
stdlib >= 1.26.0-0, < 1.26.4
Patched in:
Source: https://osv.dev/vulnerability/GO-2026-5039