VDB

RHSA-2026%3A19133

RHSA-2026%3A19133 PUBLISHED CVSS 7.800000190734863 HIGH

The Go standard library function net/url.Parse insufficiently validated the host/authority component and accepted some invalid URLs by effectively treating garbage before an IP-literal as ignorable. The function should have rejected this as invalid.

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatgit-lfs-debuginfo-0:3.7.1-4.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)3.7.1-4.el10, 3.7.1-4.el10, 3.7.1-4.el10
golang
Red Hatgit-lfs-debugsource-0:3.7.1-4.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)3.7.1-4.el10, 3.7.1-4.el10, 3.7.1-4.el10
Red Hatgit-lfs-debugsource
Red Hatgit-lfs-0:3.7.1-4.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)3.7.1-4.el10, 3.7.1-4.el10, 3.7.1-4.el10
Red Hatgit-lfs-debugsource-0:3.7.1-4.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)3.7.1-4.el10, 3.7.1-4.el10, 3.7.1-4.el10
Red Hatgit-lfs-debugsource-0:3.7.1-4.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)3.7.1-4.el10, 3.7.1-4.el10, 3.7.1-4.el10
Red Hatgit-lfs
Red Hatgit-lfs-0:3.7.1-4.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
Red Hatgit-lfs-debugsource-0:3.7.1-4.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)3.7.1-4.el10, 3.7.1-4.el10, 3.7.1-4.el10
Red Hatgit-lfs-0:3.7.1-4.el10_2.src as a component of Red Hat Enterprise Linux AppStream (v. 10)3.7.1-4.el10, 3.7.1-4.el10, 3.7.1-4.el10
Red Hatgit-lfs-0:3.7.1-4.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)3.7.1-4.el10, 3.7.1-4.el10, 3.7.1-4.el10
Red Hatgit-lfs-debuginfo-0:3.7.1-4.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)3.7.1-4.el10, 3.7.1-4.el10, 3.7.1-4.el10
Red Hatgit-lfs-0:3.7.1-4.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)3.7.1-4.el10, 3.7.1-4.el10, 3.7.1-4.el10
Red Hatgit-lfs-0:3.7.1-4.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)3.7.1-4.el10, 3.7.1-4.el10, 3.7.1-4.el10
Red Hatgit-lfs-debuginfo-0:3.7.1-4.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)3.7.1-4.el10, 3.7.1-4.el10, 3.7.1-4.el10
Red Hatgit-lfs-debuginfo-0:3.7.1-4.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)3.7.1-4.el10, 3.7.1-4.el10, 3.7.1-4.el10

Timeline

  • May 19, 2026 CVE Published
  • Aug 23, 2026 CVE Updated
  • Aug 23, 2026 Distribution Patch
  • Aug 23, 2026 Distribution Patch
  • Aug 23, 2026 Security Advisory
  • Aug 23, 2026 Security Advisory
  • Aug 23, 2026 Security Advisory
  • Aug 23, 2026 Security Advisory
  • Aug 23, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›