[CLSA-2026:1781256571] golang: Fix of 5 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-06-12 09:29:55 UTC
Description:
- CVE-2026-27142: fix missing escaping of URLs in meta tag content attributes in html/template by tracking the url= portion of the content attribute and applying URL escaping (prerequisite for CVE-2026-39823) - CVE-2026-39826: fix escaper bypass in html/template by treating script type attributes that are empty or whitespace-only as JavaScript - CVE-2026-39825: fix query parameter smuggling in net/http/httputil ReverseProxy by reencoding outbound queries that exceed the urlmaxqueryparams limit so Rewrite hooks cannot be bypassed - CVE-2026-39819: fix 'go bug' writing files with predictable names in the system temporary directory by creating a private directory with os.MkdirTemp, preventing symlink-based file overwrite - CVE-2026-39817: fix 'go tool pack' extracting archive entries to arbitrary filesystem locations by refusing to extract files with directory components - CVE-2026-39823: fix XSS in html/template where ASCII whitespace around the '=' rune in a meta tag content attribute URL bypassed URL escaping
Updated packages:
  • go-toolset-1.25.7-1.el9_6.tuxcare.els10.x86_64.rpm
    sha:540b1cadfedc65152b0377e26b506d65b7a651281b71d8ee0f7cae65d19c04e6
  • golang-1.25.7-1.el9_6.tuxcare.els10.x86_64.rpm
    sha:c1ee1bbb35d964be3c42eb4b37787f380b8ceec406f3f070ec2d45fb8fe527cf
  • golang-bin-1.25.7-1.el9_6.tuxcare.els10.x86_64.rpm
    sha:1070f8711e04b112d5379de4c8b3a0f5d77b34e5a3c16e09b2285ed370eaee4e
  • golang-docs-1.25.7-1.el9_6.tuxcare.els10.noarch.rpm
    sha:498b8cb12a2e5f3bc331ee94cf311cf36c2bd9f770fc20c476fbb4e29b505f2f
  • golang-misc-1.25.7-1.el9_6.tuxcare.els10.noarch.rpm
    sha:a459e50d12294792ce1f30b36f70096b14ac6268e537679383a6ff76a5e65308
  • golang-race-1.25.7-1.el9_6.tuxcare.els10.x86_64.rpm
    sha:7a2a8560620d8963666898077b7965c45224f2314ef17d7091f3ab4dcf882fbe
  • golang-src-1.25.7-1.el9_6.tuxcare.els10.noarch.rpm
    sha:24b75b962b5e2a05c31a3ca008fd1e5f35e48d52522508a4d8938172f96e4dd4
  • golang-tests-1.25.7-1.el9_6.tuxcare.els10.noarch.rpm
    sha:212633af5030985b7f608b736ac7b464773a089df195dbdbd600f7bf55697572
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.