VDB

RHSA-2026%3A2921

RHSA-2026%3A2921 PUBLISHED CVSS 7.5 HIGH

A flaw was found in golang. A remote attacker could exploit this vulnerability by providing a specially crafted certificate during the error string construction process within the `HostnameError.Error()` function. This flaw, caused by unbounded string concatenation, leads to excessive resource consumption. Successful exploitation can result in a denial of service (DoS) for the affected system.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatregistry.redhat.io/rhtas/createtree-rhel9@sha256:7a1e465f93e0560194b7d5d27b46453a0dd4ebb4072235da1ffbe4ccff91d452_amd64 as a component of Red Hat Trusted Artifact Signer 1.2*, *, *
Red Hatregistry.redhat.io/rhtas/createtree-rhel9@sha256:7a1e465f93e0560194b7d5d27b46453a0dd4ebb4072235da1ffbe4ccff91d452_amd64 as a component of Red Hat Trusted Artifact Signer 1.2registry.redhat.io/rhtas/createtree-rhel9@sha256:7a1e465f93e0560194b7d5d27b46453a0dd4ebb4072235da1ffbe4ccff91d452_amd64, registry.redhat.io/rhtas/createtree-rhel9@sha256:7a1e465f93e0560194b7d5d27b46453a0dd4ebb4072235da1ffbe4ccff91d452_amd64, registry.redhat.io/rhtas/createtree-rhel9@sha256:7a1e465f93e0560194b7d5d27b46453a0dd4ebb4072235da1ffbe4ccff91d452_amd64
golangGo
Red HatRed Hat Trusted Artifact Signer

Timeline

  • Feb 18, 2026 CVE Published
  • Apr 24, 2026 Distribution Patch
  • Apr 24, 2026 Distribution Patch
  • Apr 24, 2026 Security Advisory
  • Apr 24, 2026 Security Advisory
  • Apr 24, 2026 Security Advisory
  • Jul 8, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›