Red Hat disclosed and remediated CVE-2026-39820, a high-severity denial-of-service flaw in Go's net/mail package that can be triggered with crafted email input. The bug affects functions including ParseAddress, ParseAddressList, and ParseDate, where malicious input can drive excessive CPU consumption and memory allocation. Red Hat said the issue has been addressed across RHEL 8, 9, and 10, including RHEL 10.0 EUS and RHEL 9.6 EUS, following its original tracking in Bugzilla as bug 2467820.
On 2026-08-19, Red Hat shipped Important security updates for OpenShift Container Platform 4.19.43 and Red Hat build of MicroShift 4.19.43. Advisory RHSA-2026:54552 updated OpenShift packages and images to fix three Go denial-of-service issues—CVE-2026-33811 in net and CVE-2026-39820 plus CVE-2026-42499 in net/mail—while RHSA-2026:54883 delivered MicroShift RPM and image updates for CVE-2026-39820. Red Hat urged OpenShift and MicroShift 4.19 users on supported RHEL 8 and RHEL 9 platforms, including x86_64, ppc64le, s390x, and aarch64, to upgrade through the appropriate release channels and documented update procedures.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:60304 for RHEL 9, updating Go packages to version 1.26.7+1 for the 9.8.z stream. The Important advisory remediates six Go vulnerabilities, including denial-of-service issues in encoding/asn1, net/url, net/http, crypto/tls, and encoding/xml, plus an html/template cross-site scripting flaw.
Red Hat published RHSA-2026:56852 for RHCOS systems running OpenShift Container Platform 4.16.69. The Important update remediates CVE-2026-39820 alongside Go flaws including CVE-2025-68121, CVE-2026-25679, CVE-2026-32280, CVE-2026-33811, and CVE-2026-42499.
Red Hat issued RHSA-2026:57914 for RHCOS 4 systems running Red Hat build of MicroShift 4.18.54. The Important-severity update remediates the Go net/mail denial-of-service flaws CVE-2026-39820 and CVE-2026-42499.
Red Hat published RHSA-2026:57845 for Red Hat Enterprise Linux CoreOS 4 systems using Red Hat build of MicroShift 4.16.69. The advisory updates MicroShift-related packages to remediate CVE-2026-39820 along with CVE-2026-33814, CVE-2026-39821, and CVE-2026-42499.
On 2026-08-19, Red Hat issued RHSA-2026:54883 for Red Hat build of MicroShift 4.19.43. The advisory delivers updated RPM packages and images to address CVE-2026-39820 and instructs MicroShift 4.19 users to apply the update.
On 2026-08-19, Red Hat issued RHSA-2026:54552 for Red Hat OpenShift Container Platform 4.19.43. The advisory includes fixes for CVE-2026-39820 in Go net/mail, alongside CVE-2026-33811 and CVE-2026-42499, and advises users to upgrade.
OSIDB Bzimport reported Bug 2467820 for CVE-2026-39820 on 2026-05-07. The bug tracks a high-severity denial-of-service flaw in Go's net/mail package triggered by crafted email inputs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
9 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.