Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-42507

Опубликовано: 02 июн. 2026
Источник: debian
EPSS Низкий

Описание

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.26fixed1.26.4-1package
golang-1.25fixed1.25.11-1package
golang-1.24removedpackage
golang-1.24no-dsatrixiepackage
golang-1.19removedpackage
golang-1.19no-dsabookwormpackage
golang-1.15removedpackage
golang-1.15postponedbullseyepackage

Примечания

  • https://github.com/golang/go/issues/79346

  • https://github.com/golang/go/commit/ec1c380418ec6a0da28d4519872e2b81ba9152ba (go1.26.4)

  • https://github.com/golang/go/commit/449dafea7264878e73acc58cbd330e0ee6630030 (go1.25.11)

EPSS

Процентиль: 30%
0.0037
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 месяцев назад

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

CVSS3: 5.3
redhat
около 2 месяцев назад

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

CVSS3: 5.3
nvd
около 2 месяцев назад

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

CVSS3: 5.3
msrc
около 2 месяцев назад

Arbitrary inputs are included in errors without any escaping in net/textproto

rocky
около 1 месяца назад

Moderate: golang security, bug fix, and enhancement update

EPSS

Процентиль: 30%
0.0037
Низкий