From Our Security Partners
CVE-2026-39823 Bypass of meta content URL escaping causes XSS in html/template
Information published.
CVE-2026-39820 Quadratic string concatentation in consumeComment in net/mail
Information published.
CVE-2026-39825 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil
Information published.
CVE-2026-42499 Quadratic string concatenation in consumePhrase in net/mail
Information published.
CVE-2026-39836 Panic in Dial and LookupPort when handling NUL byte on Windows in net
Information published.
CVE-2026-33814 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
Information published.
CVE-2026-43249 9p/xen: protect xen_9pfs_front_free against concurrent calls
Information published.
CVE-2026-31767 drm/i915/dsi: Don’t do DSC horizontal timing adjustments in command mode
Information published.