Red Hat released Important security updates for Go packages in Red Hat Enterprise Linux 9 and Red Hat Enterprise Linux 10, addressing CVE-2026-27137 and CVE-2026-25679 across multiple architectures and support channels. The advisories, RHSA-2026:19181 for RHEL 9 and RHSA-2026:19022 for RHEL 10, update Go to 1.26.2+2 in the RHEL 9.8.z stream and 1.26.2-2.el10_2 in RHEL 10.2, with packages provided for x86_64, s390x, ppc64le, and aarch64 systems, including Extended Update Support and Extended Life Cycle offerings.
The more detailed flaw, CVE-2026-25679, affects Go's net/url.Parse function, which can incorrectly accept malformed URLs by failing to properly validate the host or authority component and by treating garbage before an IPv6 literal as ignorable. Red Hat rated that issue Important with a CVSS 7.5 score and said no qualifying mitigation was available, while the second bug, CVE-2026-27137, affects Go's crypto/x509 handling of email constraints. Organizations running Go workloads or development toolchains on supported RHEL releases should prioritize the updated golang and go-toolset packages to close both parsing and certificate-validation exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On May 19, 2026, Red Hat issued RHSA-2026:19022, an Important security advisory for golang packages in Red Hat Enterprise Linux 10. The update ships golang-1.26.2-2.el10_2, updates Go to version 1.26.2+2 for the RHEL 10.2.z stream, and fixes CVE-2026-27137 and CVE-2026-25679.
On May 19, 2026, Red Hat issued RHSA-2026:19181, an Important security advisory for golang packages in Red Hat Enterprise Linux 9. The update brings Go to version 1.26.2+2 for the RHEL 9.8.z stream and fixes CVE-2026-27137 and CVE-2026-25679 across multiple RHEL 9 variants and architectures.
Red Hat published its CVE page for CVE-2026-25679, documenting incorrect parsing of IPv6 host literals in Go's net/url.Parse and listing affected and fixed Red Hat components. The page rates the issue Important and maps it to CWE-1286.
Red Hat's CVE page for CVE-2026-25679 was last modified on March 19, 2026 at 10:34:02 AM UTC. The entry describes the issue as an Important-severity flaw with CVSS 7.5 and no qualifying mitigation available.
Red Hat's CVE entry states that CVE-2026-25679 was public on March 6, 2026. The flaw affects Go's net/url.Parse handling of malformed URLs with IPv6 host literals.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.