Vulnerability Description
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Golang | Net | < 0.55.0 |
Related Weaknesses (CWE)
References
- https://go.dev/cl/767220Issue Tracking
- https://go.dev/issue/78760Issue Tracking
- https://groups.google.com/g/golang-announce/c/94pEornpRlI
- https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8Mailing List
- https://pkg.go.dev/vuln/GO-2026-5026Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:23262
- https://access.redhat.com/errata/RHSA-2026:23264
- https://access.redhat.com/errata/RHSA-2026:26546
- https://access.redhat.com/errata/RHSA-2026:26547
- https://access.redhat.com/errata/RHSA-2026:30650
- https://access.redhat.com/errata/RHSA-2026:30651
- https://access.redhat.com/errata/RHSA-2026:30853
- https://access.redhat.com/errata/RHSA-2026:30854
- https://access.redhat.com/errata/RHSA-2026:30855
- https://access.redhat.com/errata/RHSA-2026:33155
FAQ
What is CVE-2026-39821?
CVE-2026-39821 is a vulnerability with a CVSS score of 9.6 (CRITICAL). The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com"...
How severe is CVE-2026-39821?
CVE-2026-39821 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-39821?
Check the references section above for vendor advisories and patch information. Affected products include: Golang Net.