Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-39821

Опубликовано: 22 мая 2026
Источник: nvd
CVSS3: 9.6
CVSS3: 8.2
EPSS Низкий

Описание

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:golang:net:*:*:*:*:*:go:*:*
Версия до 0.55.0 (исключая)

EPSS

Процентиль: 48%
0.00655
Низкий

9.6 Critical

CVSS3

8.2 High

CVSS3

Дефекты

CWE-1289
CWE-1289

Связанные уязвимости

CVSS3: 9.6
ubuntu
2 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 8.2
redhat
2 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 10
msrc
2 месяца назад

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

CVSS3: 9.6
debian
2 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ...

suse-cvrf
около 1 месяца назад

Security update for golang-github-prometheus-alertmanager

EPSS

Процентиль: 48%
0.00655
Низкий

9.6 Critical

CVSS3

8.2 High

CVSS3

Дефекты

CWE-1289
CWE-1289