Red Hat released Important security updates for Go across RHEL 8, RHEL 9, and RHEL 10, updating packages to Go 1.26.5+1 and addressing multiple vulnerabilities in the toolchain and bundled libraries. The advisories cover CVE-2026-39821, a privilege-escalation flaw in golang.org/x/net/idna caused by incorrect Punycode label handling that can bypass ASCII-only authorization checks, and **CVE-2026-39822,** a Unix os.Root` symlink-following bug that can enable directory traversal outside an intended root. Red Hat said the fixes apply across standard, extended support, and lifecycle variants on x86_64, s390x, ppc64le, and aarch64 systems.
The updates also include additional Go-related fixes depending on platform, including CVE-2026-42505 in crypto/tls, which can leak pre-shared key identities during Encrypted Client Hello (ECH) handshakes and allow passive observers to correlate connections, and CVE-2026-27145 on RHEL 8, described as a denial-of-service issue in crypto/x509. Red Hat rated CVE-2026-39821 at CVSS 8.2 and CVE-2026-39822 at CVSS 7.8, and said there is no mitigation for the os.Root flaw other than updating to fixed Go releases such as 1.25.12 or 1.26.5.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:47719 for golang packages in Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related RHEL 9.2 channels, rated Important. The update brought Go to 1.25.9+2 and fixed CVE-2025-68121, CVE-2026-32281, CVE-2026-32282, CVE-2026-32283, CVE-2026-32280, CVE-2026-27144, and CVE-2026-27143.
Red Hat lists RHSA-2026:42078, RHSA-2026:42079, and RHSA-2026:42080 as fixing CVE-2026-39821 across Ansible Automation Platform 2.5, 2.6, and 2.7 receptor builds for RHEL 9 and RHEL 10, plus 2.5 for RHEL 8.
Red Hat published RHSA-2026:38995 for the go-toolset:rhel8 module on Red Hat Enterprise Linux 8, updating Go to 1.26.5+1 and fixing CVE-2026-39821, CVE-2026-27145, and CVE-2026-39822.
Red Hat published RHSA-2026:37436 for Red Hat Enterprise Linux 10, updating Go to 1.26.5+1 and fixing CVE-2026-39821 and CVE-2026-39822 while also listing CVE-2026-42505.
Red Hat published RHSA-2026:37435 for Red Hat Enterprise Linux 9, updating Go to 1.26.5+1 and fixing CVE-2026-39821 and CVE-2026-39822 while also listing CVE-2026-42505.
Red Hat states that CVE-2026-42505, a Moderate information disclosure flaw in Go crypto/tls affecting ECH handshakes, became public on this date.
Red Hat published its CVE entry for CVE-2026-39822, describing an Important-severity os.Root symlink-traversal flaw in Go on Unix systems and noting fixes in Go 1.25.12 and 1.26.5.
Red Hat lists RHSA-2026:35826 for grafana-pcp and RHSA-2026:35827 for grafana as fixes for CVE-2026-39821 in Red Hat Enterprise Linux 10.
Red Hat says RHSA-2026:34357 fixed CVE-2026-39821 in Red Hat Enterprise Linux 10 opentelemetry-collector.
Red Hat lists RHSA-2026:30855 as fixing CVE-2026-39821 for Red Hat Enterprise Linux 10 git-lfs, showing one of the earliest product remediations for the flaw.
Red Hat's CVE entry states that CVE-2026-39821, a privilege escalation flaw in golang.org/x/net/idna caused by incorrect Punycode label handling, became public on this date.
Red Hat published RHSA-2026:10219 for Red Hat Enterprise Linux 9, rating it Important and updating Go to version 1.25.9+2. The advisory fixed multiple Go vulnerabilities, including CVE-2026-32282, CVE-2026-32283, CVE-2026-32280, CVE-2026-27144, and CVE-2026-27143.
Red Hat states RHSA-2026:54773 fixed CVE-2026-42505 for OpenShift distributed tracing 3.10.1 components including opentelemetry-collector-rhel9 and opentelemetry-rhel9-operator.
Red Hat says RHSA-2026:48891 fixed CVE-2026-39822 in Red Hat Advanced Cluster Security for Kubernetes 4.11 rhacs-main-rhel9.
Red Hat published its CVE page for CVE-2026-39821, rating the flaw Important, assigning CVSS 8.2, and stating exposure spans products that ship the Go toolchain or bundle golang.org/x/net.
Red Hat's CVE-2026-39822 entry says RHSA-2026:38494 fixed RHEL 10 buildah, RHSA-2026:38493 fixed RHEL 9 buildah, and RHSA-2026:38878 fixed RHEL 9 podman for the os.Root flaw.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 40 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
9 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcego.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.