Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-39820

Опубликовано: 07 мая 2026
Источник: debian

Описание

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.25fixed1.25.10-1package
golang-1.26fixed1.26.3-1package
golang-1.24removedpackage
golang-1.24no-dsatrixiepackage
golang-1.19removedpackage
golang-1.19no-dsabookwormpackage
golang-1.15removedpackage
golang-1.15postponedbullseyepackage

Примечания

  • https://go-review.googlesource.com/c/go/+/759940

  • https://github.com/golang/go/issues/78566

  • https://groups.google.com/g/golang-announce/c/qcCIEXso47M

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

CVSS3: 7.5
redhat
3 месяца назад

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

CVSS3: 7.5
nvd
3 месяца назад

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

msrc
3 месяца назад

Quadratic string concatentation in consumeComment in net/mail

CVSS3: 7.5
github
3 месяца назад

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.