The Go project released Go 1.26.4 and Go 1.25.11 with three security fixes, including two denial-of-service issues that could be triggered by crafted input. One flaw, tracked as CVE-2026-42504, affects mime.WordDecoder.DecodeHeader, where malicious MIME headers containing many invalid encoded words can drive quadratic or near-quadratic parsing behavior and cause excessive CPU consumption. Public issue details describe an attack pattern using repeated malformed encoded-word prefixes that force repeated parsing work before a terminating ?= sequence.
The same releases also fix CVE-2026-27145, a quadratic-performance problem in crypto/x509 hostname verification when certificates contain large DNS SAN lists, and CVE-2026-42507, where net/textproto functions could return unescaped attacker-controlled input in error messages, creating a risk of misleading log entries or terminal control-sequence injection. The Go team credited p4p3r and Jakub Ciolek for reporting two of the issues and directed users to upgrade to the patched versions.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The Go team released Go 1.26.4 and Go 1.25.11 as minor point releases containing three security fixes. The fixes addressed CVE-2026-42504 in mime, CVE-2026-42507 in net/textproto, and CVE-2026-27145 in crypto/x509.
A public Go security issue tracking quadratic or near-quadratic complexity in mime.WordDecoder.DecodeHeader was opened, documenting that malicious MIME header input could trigger excessive parsing work. The issue credits p4p3r for reporting it and assigns CVE-2026-42504.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcegroups.google.com
Open sourcego.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.