Количество 148
Количество 148
GHSA-w2q5-6q6x-x959
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
CVE-2026-39821
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ...
openSUSE-SU-2026:21562-1
Security update for go-sendxmpp
openSUSE-SU-2026:21494-1
Security update for gh
openSUSE-SU-2026:21433-1
Security update for hauler
openSUSE-SU-2026:21432-1
Security update for gh
openSUSE-SU-2026:21413-1
Security update for google-cloud-sap-agent
openSUSE-SU-2026:21157-1
Security update for golang-github-prometheus-alertmanager
openSUSE-SU-2026:20994-1
Security update for helm
openSUSE-SU-2026:20888-1
Security update for apptainer
openSUSE-SU-2026:20853-1
Security update for hauler
SUSE-SU-2026:3473-1
Security update for aws-iam-authenticator
SUSE-SU-2026:3472-1
Security update for google-cloud-sap-agent
SUSE-SU-2026:3471-1
Security update for google-cloud-sap-agent
SUSE-SU-2026:3421-1
Security update for prometheus-ha_cluster_exporter
SUSE-SU-2026:3416-1
Security update for prometheus-ha_cluster_exporter
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-w2q5-6q6x-x959 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". | CVSS3: 10 | 1% Низкий | 4 месяца назад | |
CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". | CVSS3: 9.6 | 1% Низкий | 4 месяца назад | |
CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". | CVSS3: 8.2 | 1% Низкий | 4 месяца назад | |
CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". | CVSS3: 9.6 | 1% Низкий | 4 месяца назад | |
CVE-2026-39821 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | CVSS3: 10 | 1% Низкий | 4 месяца назад | |
CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ... | CVSS3: 9.6 | 1% Низкий | 4 месяца назад | |
openSUSE-SU-2026:21562-1 Security update for go-sendxmpp | 1% Низкий | около 1 месяца назад | ||
openSUSE-SU-2026:21494-1 Security update for gh | 1% Низкий | около 2 месяцев назад | ||
openSUSE-SU-2026:21433-1 Security update for hauler | 1% Низкий | около 2 месяцев назад | ||
openSUSE-SU-2026:21432-1 Security update for gh | 1% Низкий | около 2 месяцев назад | ||
openSUSE-SU-2026:21413-1 Security update for google-cloud-sap-agent | 1% Низкий | около 2 месяцев назад | ||
openSUSE-SU-2026:21157-1 Security update for golang-github-prometheus-alertmanager | 1% Низкий | 3 месяца назад | ||
openSUSE-SU-2026:20994-1 Security update for helm | 1% Низкий | 3 месяца назад | ||
openSUSE-SU-2026:20888-1 Security update for apptainer | 1% Низкий | 3 месяца назад | ||
openSUSE-SU-2026:20853-1 Security update for hauler | 1% Низкий | 3 месяца назад | ||
SUSE-SU-2026:3473-1 Security update for aws-iam-authenticator | 1% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:3472-1 Security update for google-cloud-sap-agent | 1% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:3471-1 Security update for google-cloud-sap-agent | 1% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:3421-1 Security update for prometheus-ha_cluster_exporter | 1% Низкий | около 2 месяцев назад | ||
SUSE-SU-2026:3416-1 Security update for prometheus-ha_cluster_exporter | 1% Низкий | около 2 месяцев назад |
Уязвимостей на страницу