{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20762-1","published":"2026-05-17T20:16:08Z","modified":"2026-05-19T08:45:11.093288855Z","related":["CVE-2026-33811","CVE-2026-33814","CVE-2026-39817","CVE-2026-39819","CVE-2026-39820","CVE-2026-39823","CVE-2026-39825","CVE-2026-39826","CVE-2026-39836","CVE-2026-42499","CVE-2026-42501"],"upstream":["CVE-2026-33811","CVE-2026-33814","CVE-2026-39817","CVE-2026-39819","CVE-2026-39820","CVE-2026-39823","CVE-2026-39825","CVE-2026-39826","CVE-2026-39836","CVE-2026-42499","CVE-2026-42501"],"summary":"Security update for go1.26","details":"This update for go1.26 fixes the following issues\n\nSecurity issues:\n\n- CVE-2026-33811: net: crash when handling long CNAME response (bsc#1264508).\n- CVE-2026-33814: net/http: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1264506).\n- CVE-2026-39817: cmd/go: \"go tool pack\" does not sanitize output paths (bsc#1264505).\n- CVE-2026-39819: cmd/go: \"go bug\" follows symlinks in predictable temporary filenames (bsc#1264504).\n- CVE-2026-39820: net/mail: quadratic string concatentation in consumeComment (bsc#1264503).\n- CVE-2026-39823: html/template: bypass of meta content URL escaping causes XSS (bsc#1264509).\n- CVE-2026-39825: net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters\n  (bsc#1264500).\n- CVE-2026-39826: html/template: escaper bypass leads to XSS (bsc#1264507).\n- CVE-2026-39836: net: panic in Dial and LookupPort when handling NUL byte on Windows (bsc#1264501).\n- CVE-2026-42499: net/mail: quadratic string concatenation in consumePhrase (bsc#1264502).\n- CVE-2026-42501: cmd/go: malicious module proxy can bypass checksum database (bsc#1264499).\n\nNon security issues:\n\n- Updated to go1.26.3 (bsc#1255111).\n- Go packages miss binutils-gold dependency (bsc#1170826).\n","references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1170826"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255111"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264499"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264500"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264501"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264502"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264503"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264504"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264505"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264506"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264507"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264508"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264509"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33811"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33814"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39817"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39819"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39820"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39823"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39825"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39826"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39836"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42499"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42501"}]}