Red Hat released Important-rated updates for Go and osbuild-composer across Red Hat Enterprise Linux 9 update channels. The Go update, golang-1.26.5-1.el9_4 for RHEL 9.4, addresses 14 vulnerabilities involving denial of service, cross-site scripting (XSS), arbitrary file writes and overwrites, symlink-based directory traversal, checksum-validation bypasses, privilege escalation, and security-control bypasses. One tracked issue, CVE-2026-39819, allows the go bug command to write to predictable files in the system temporary directory; a local attacker able to create symlinks there could redirect those writes to an arbitrary target file.
Separate osbuild-composer updates remediate flaws in Go's golang.org/x/net dependencies. RHSA-2026:59560 provides osbuild-composer-132.2-11.el9_6 for RHEL 9.6, while RHSA-2026:59562 provides osbuild-composer-101.3-4.el9_4.5 for RHEL 9.4 SAP Solution update services. The advisories address HTML parsing and rendering flaws—CVE-2026-25681, CVE-2026-27136, and CVE-2026-42502—that can enable XSS, including potential arbitrary code execution through XSS, plus CVE-2026-39821 in the RHEL 9.4 package, involving improper Punycode-label processing that can enable privilege escalation. Organizations should apply the updated packages through their applicable RHEL, EUS, AUS, SAP, or Extended Life Cycle channels.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2026:59560 for osbuild-composer across affected RHEL 9.6 offerings. The osbuild-composer-132.2-11.el9_6 update fixes golang.org/x/net/html vulnerabilities CVE-2026-27136, CVE-2026-25681, and CVE-2026-42502.
Red Hat issued Important-rated RHSA-2026:59562 for osbuild-composer on RHEL 9.4 Update Services for SAP Solutions. The osbuild-composer 101.3-4.el9_4.5 update fixes CVE-2026-39821 and three golang.org/x/net/html XSS-related flaws: CVE-2026-27136, CVE-2026-25681, and CVE-2026-42502.
Red Hat issued Important-rated RHSA-2026:57649, supplying Go 1.26.5-1.el9_4 for RHEL 9.4 update channels. The update remediates 14 CVEs, including CVE-2026-39819, covering issues such as denial of service, XSS, arbitrary file write, symlink traversal, integrity bypass, privilege escalation, and security-control bypass.
Red Hat addressed CVE-2026-56858, in which pathological input could prematurely close an unescaped forward slash and permit attacker-controlled content injection, potentially causing cross-site scripting. Fixes were issued for RHEL 8, 9, and 10 through RHSA-2026:60305, RHSA-2026:60304, and RHSA-2026:60306, respectively.
Red Hat documented CVE-2026-39819, in which the Go "go bug" command writes predictable temporary-file names that an attacker can pre-create as symlinks to overwrite another file. Red Hat stated that fixes were available for RHEL 8, 9, 10, RHEL 10.0 EUS, and RHEL 9.6 EUS through associated RHSA advisories.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.