VDB

RHSA-2026%3A2371

RHSA-2026%3A2371 PUBLISHED CVSS 7.5 HIGH

A flaw was found in golang. A remote attacker could exploit this vulnerability by providing a specially crafted certificate during the error string construction process within the `HostnameError.Error()` function. This flaw, caused by unbounded string concatenation, leads to excessive resource consumption. Successful exploitation can result in a denial of service (DoS) for the affected system.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatregistry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:9a25718e20cc0f33082f4346cbfb63d71cb77c5c08bbcc4021ffa4552a4df16b_amd64 as a component of Red Hat Web Terminal 1.12registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:9a25718e20cc0f33082f4346cbfb63d71cb77c5c08bbcc4021ffa4552a4df16b_amd64, registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:9a25718e20cc0f33082f4346cbfb63d71cb77c5c08bbcc4021ffa4552a4df16b_amd64, registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:9a25718e20cc0f33082f4346cbfb63d71cb77c5c08bbcc4021ffa4552a4df16b_amd64
Red Hatregistry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:335c03975dd985354a57ac13f184918157de6e1cf0f0003127d01cf90467c3c2_amd64 as a component of Red Hat Web Terminal 1.12*, *, *
Red Hatregistry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:47611b41d24a5d1382f279b46895ff6aaa12c39049f02c080fa464660ea0704b_amd64 as a component of Red Hat Web Terminal 1.12*, registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:47611b41d24a5d1382f279b46895ff6aaa12c39049f02c080fa464660ea0704b_amd64, registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:47611b41d24a5d1382f279b46895ff6aaa12c39049f02c080fa464660ea0704b_amd64
Red Hatregistry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:47611b41d24a5d1382f279b46895ff6aaa12c39049f02c080fa464660ea0704b_amd64 as a component of Red Hat Web Terminal 1.12registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:47611b41d24a5d1382f279b46895ff6aaa12c39049f02c080fa464660ea0704b_amd64, registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:47611b41d24a5d1382f279b46895ff6aaa12c39049f02c080fa464660ea0704b_amd64, registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:47611b41d24a5d1382f279b46895ff6aaa12c39049f02c080fa464660ea0704b_amd64
Red Hatregistry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:335c03975dd985354a57ac13f184918157de6e1cf0f0003127d01cf90467c3c2_amd64 as a component of Red Hat Web Terminal 1.12*, registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:335c03975dd985354a57ac13f184918157de6e1cf0f0003127d01cf90467c3c2_amd64, registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:335c03975dd985354a57ac13f184918157de6e1cf0f0003127d01cf90467c3c2_amd64
golangGo
Red Hatregistry.redhat.io/web-terminal/web-terminal-operator-bundle@sha256:a16c875367810b15a5aa0da2c128d20f295866a5dab65f93deeaa78621b6135c_amd64 as a component of Red Hat Web Terminal 1.12registry.redhat.io/web-terminal/web-terminal-operator-bundle@sha256:a16c875367810b15a5aa0da2c128d20f295866a5dab65f93deeaa78621b6135c_amd64, registry.redhat.io/web-terminal/web-terminal-operator-bundle@sha256:a16c875367810b15a5aa0da2c128d20f295866a5dab65f93deeaa78621b6135c_amd64, *
Red Hatregistry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:9a25718e20cc0f33082f4346cbfb63d71cb77c5c08bbcc4021ffa4552a4df16b_amd64 as a component of Red Hat Web Terminal 1.12*, *, registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:9a25718e20cc0f33082f4346cbfb63d71cb77c5c08bbcc4021ffa4552a4df16b_amd64
Red Hatregistry.redhat.io/web-terminal/web-terminal-operator-bundle@sha256:a16c875367810b15a5aa0da2c128d20f295866a5dab65f93deeaa78621b6135c_amd64 as a component of Red Hat Web Terminal 1.12*, *, *

Timeline

  • Feb 9, 2026 CVE Published
  • Apr 24, 2026 Distribution Patch
  • Apr 24, 2026 Distribution Patch
  • Apr 24, 2026 Security Advisory
  • Apr 24, 2026 Security Advisory
  • Jul 8, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›