Red Hat issued multiple Important advisories to remediate two Go denial-of-service vulnerabilities affecting RHEL and downstream products: CVE-2026-33811, a crash-causing flaw in Go's net package when LookupCNAME processes an excessively long CNAME response with the cgo DNS resolver, and CVE-2026-27145, a performance DoS issue in crypto/x509 hostname verification caused by excessive processing of DNS Subject Alternative Name entries. The flaws can be triggered by malicious DNS or certificate inputs and impact software built on vulnerable Go components, with fixes published for Red Hat Enterprise Linux 7, 8, 9, and 10 streams as well as Extended Update Support and Extended Lifecycle channels.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Important advisory RHSA-2026:61313 for the rhc package on RHEL 10 and RHEL 10.0 EUS. The update fixes CVE-2026-33811, a Go net LookupCNAME denial-of-service flaw, and CVE-2026-33810, a Go crypto/x509 certificate-validation bypass.
Red Hat issued RHSA-2026:54168 for rhc-worker-playbook on RHEL 10.0 Extended Update Support, releasing version 0.2.3-6.el10_0 packages that fix CVE-2026-33811 and CVE-2026-27145.
Red Hat issued RHSA-2026:50319 for Ansible Automation Platform 2.5, including fixes for CVE-2026-33811 in automation-gateway-proxy and CVE-2026-27145 in receptor alongside other vulnerabilities.
Red Hat issued RHSA-2026:49703 for the delve package on RHEL 10.0 Extended Update Support, shipping delve 1.26.1-1.el10_0 and fixing CVE-2026-33811 and CVE-2026-27145.
Red Hat issued RHSA-2026:48151 for Cryostat 4 on RHEL 9, listing the cryostat-storage-rhel9 component as fixed for CVE-2026-33811. This adds a new affected Red Hat product receiving a security fix for the Go net LookupCNAME denial-of-service flaw.
Red Hat issued RHSA-2026:42946 for rhc-worker-playbook on RHEL 10, fixing both CVE-2026-33811 and CVE-2026-27145 in updated rhc-worker-playbook 0.2.10-1.el10_2 packages.
Red Hat issued RHSA-2026:39573 for yggdrasil in Red Hat Enterprise Linux 10, releasing yggdrasil 0.4.9.2-1.el10_2 and fixing CVE-2026-33811 alongside CVE-2026-39821 and CVE-2026-27145. The advisory was rated Important and applied across multiple RHEL 10 architectures and channels.
Red Hat issued RHSA-2026:38504 for the container-tools:rhel8 module in Red Hat Enterprise Linux 8, fixing CVE-2026-33811 alongside CVE-2026-39835 and CVE-2026-57231. The Important advisory released updated Podman, Buildah, Skopeo, and runc packages across multiple RHEL 8 architectures and Extended Life Cycle variants.
Red Hat's Bugzilla record says OSIDB Bzimport recorded the description for CVE-2026-33811, a Go net LookupCNAME denial-of-service flaw caused by a double-free on very long CNAME responses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
10 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.