Количество 211
Количество 211
RLSA-2026:65534
Important: image-builder security update
ELSA-2026-65534-0
ELSA-2026-65534-0: image-builder security update (IMPORTANT)
SUSE-SU-2026:3102-1
Security update for go1.26-openssl
SUSE-SU-2026:3047-1
Security update for go1.26-openssl
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
CVE-2026-39821
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ...
RLSA-2026:39319
Important: git-lfs security update
RLSA-2026:39272
Important: git-lfs security update
RLSA-2026:39266
Important: git-lfs security update
RLSA-2026:36617
Important: oci-seccomp-bpf-hook security update
GHSA-497x-jcxf-m478
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
ELSA-2026-39319
ELSA-2026-39319: git-lfs security update (IMPORTANT)
ELSA-2026-39272
ELSA-2026-39272: git-lfs security update (IMPORTANT)
ELSA-2026-39266
ELSA-2026-39266: git-lfs security update (IMPORTANT)
ELSA-2026-36617
ELSA-2026-36617: oci-seccomp-bpf-hook security update (IMPORTANT)
BDU:2026-07950
Уязвимость функций LookupCNAME() языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании
SUSE-SU-2026:3151-1
Security update for go1.25-openssl
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:65534 Important: image-builder security update | 5 дней назад | |||
ELSA-2026-65534-0 ELSA-2026-65534-0: image-builder security update (IMPORTANT) | 4 дня назад | |||
SUSE-SU-2026:3102-1 Security update for go1.26-openssl | около 2 месяцев назад | |||
SUSE-SU-2026:3047-1 Security update for go1.26-openssl | 2 месяца назад | |||
CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". | CVSS3: 9.6 | 1% Низкий | 4 месяца назад | |
CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". | CVSS3: 8.2 | 1% Низкий | 4 месяца назад | |
CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". | CVSS3: 9.6 | 1% Низкий | 4 месяца назад | |
CVE-2026-39821 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | CVSS3: 10 | 1% Низкий | 4 месяца назад | |
CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ... | CVSS3: 9.6 | 1% Низкий | 4 месяца назад | |
RLSA-2026:39319 Important: git-lfs security update | 1% Низкий | 2 месяца назад | ||
RLSA-2026:39272 Important: git-lfs security update | 1% Низкий | 2 месяца назад | ||
RLSA-2026:39266 Important: git-lfs security update | 1% Низкий | 2 месяца назад | ||
RLSA-2026:36617 Important: oci-seccomp-bpf-hook security update | 1% Низкий | 2 месяца назад | ||
GHSA-497x-jcxf-m478 When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
ELSA-2026-39319 ELSA-2026-39319: git-lfs security update (IMPORTANT) | 1% Низкий | 2 месяца назад | ||
ELSA-2026-39272 ELSA-2026-39272: git-lfs security update (IMPORTANT) | 1% Низкий | 2 месяца назад | ||
ELSA-2026-39266 ELSA-2026-39266: git-lfs security update (IMPORTANT) | 1% Низкий | 2 месяца назад | ||
ELSA-2026-36617 ELSA-2026-36617: oci-seccomp-bpf-hook security update (IMPORTANT) | 1% Низкий | 2 месяца назад | ||
BDU:2026-07950 Уязвимость функций LookupCNAME() языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
SUSE-SU-2026:3151-1 Security update for go1.25-openssl | около 2 месяцев назад |
Уязвимостей на страницу