Red Hat disclosed and remediated CVE-2026-42507, a moderate-severity flaw in Golang's net/textproto package that allows attacker-controlled input to appear in returned error messages. The issue can inject misleading content into printed errors or logs, creating opportunities for operator confusion, log forgery, and misinterpretation of system events. Red Hat maps the bug to CWE-117 and assigns it a CVSS v3 score of 5.3, while noting that no acceptable mitigation is currently available under its product security criteria.
Red Hat said fixes were shipped through errata affecting multiple product lines, including Red Hat Enterprise Linux 8, 9, and 10, RHEL 9/10 Extended Update Support variants, Red Hat Hardened Images, and OpenShift distributed tracing components. Advisory RHSA-2026:29980 delivers updated Golang packages for RHEL 10 and moves Go to 1.26.4+1 in the 10.2.z stream, with coverage across architectures including x86_64, s390x, ppc64le, and aarch64; the advisory also references CVE-2026-27145 and CVE-2026-42504.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued advisory RHSA-2026:29981 to address CVE-2026-42507 in Red Hat Enterprise Linux 9. Red Hat's Bugzilla and CVE records both list RHEL 9 as fixed through this advisory.
Red Hat published RHSA-2026:29980 for golang packages in Red Hat Enterprise Linux 10, fixing CVE-2026-42507 and updating Go to version 1.26.4+1 for the RHEL 10.2.z stream. The advisory rated the security impact as Moderate.
Red Hat issued advisories RHSA-2026:23262 and RHSA-2026:23264 to fix CVE-2026-42507 in Red Hat Hardened Images for golang1-25-main and golang1-26-main. The products were listed as fixed in Red Hat's CVE record.
Red Hat made public its CVE record for CVE-2026-42504, an Important-severity denial-of-service flaw in Golang's MIME package where malformed MIME headers with many invalid encoded-words can cause excessive CPU consumption. The entry also documented mitigations and tracked affected Red Hat products.
Red Hat tracked CVE-2026-42507 as Bugzilla issue 2484205, classifying it as a medium-severity vulnerability affecting Golang's net/textproto package. The report noted that attacker-controlled input could be included in returned error messages.
Red Hat's CVE record for CVE-2026-42507 was made public, describing a Golang net/textproto flaw where returned errors include attacker-controlled input. The issue was associated with misleading or forged log and error output.
A public Go security issue was opened for CVE-2026-42507 in net/textproto, describing that attacker-controlled input could be included in error messages without escaping and lead to misleading or log-injected output. The issue noted planned fixes on the Go 1.25 and 1.26 release branches.
Red Hat issued RHSA-2026:38995 to fix CVE-2026-42507 in Red Hat Enterprise Linux 8's go-toolset:rhel8 component. The Red Hat CVE record lists RHEL 8 as fixed through this advisory.
Red Hat issued RHSA-2026:33612 for OpenShift distributed tracing 3.10.1 components affected by CVE-2026-42507, including multiple tempo-related images and bundles. The CVE record lists these components as fixed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourcego.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.