Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-39821

Опубликовано: 22 мая 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.6

Описание

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

released

1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3
esm-apps/focal

released

1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3
esm-infra-legacy/xenial

not-affected

code not present
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

not-affected

0.55.0

Показывать по

EPSS

Процентиль: 38%
0.00478
Низкий

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.2
redhat
2 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
nvd
2 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 10
msrc
2 месяца назад

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

CVSS3: 9.6
debian
2 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ...

suse-cvrf
около 1 месяца назад

Security update for golang-github-prometheus-alertmanager

EPSS

Процентиль: 38%
0.00478
Низкий

9.6 Critical

CVSS3