VDB
GCVE-110-MAGEIA-2026-276
GCVE-110-MAGEIA-2026-276
Advisory Published
The updated packages fix security vulnerabilities:
mime: quadratic complexity in WordDecoder.DecodeHeader. (CVE-2026-42504)
net/textproto: arbitrary input are included in errors without any
escaping. (CVE-2026-42507)
crypto/x509: split candidate hostname only once. (CVE-2026-27145)
os: Root escape via symlink plus trailing slash. (CVE-2026-39822)
crypto/tls: Encrypted Client Hello privacy leak. (CVE-2026-42505)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | golang | 0 (affected), 1.25.12-1.mga9 (unaffected) | — |
| Mageia | golang | 0 (affected), 1.25.12-1.mga10 (unaffected) | — |
References
Browse GCVE Records
69,133 records in the GCVE database · Updated August 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.