From Our Security Partners
CVE-2026-8177 XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences
Information published.
CVE-2026-42501 Malicious module proxy can bypass checksum database in cmd/go
Information published.
CVE-2026-39819 Invoking “go bug” follows symlinks in predictable temporary filenames in cmd/go
Information published.
CVE-2026-39823 Bypass of meta content URL escaping causes XSS in html/template
Information published.
CVE-2026-39820 Quadratic string concatentation in consumeComment in net/mail
Information published.
CVE-2026-39825 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil
Information published.
CVE-2026-42499 Quadratic string concatenation in consumePhrase in net/mail
Information published.
CVE-2026-39836 Panic in Dial and LookupPort when handling NUL byte on Windows in net
Information published.