Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.2

CVE-2026-39821: Go IDNA library allows ASCII Punycode bypass

CVE-2026-39821 · published 4 months ago
Summary

The Go language IDNA package accepts specially crafted domain names that look like regular ASCII addresses but are actually Punycode strings. This can trick programs that check hostnames, letting an attacker gain higher privileges or bypass restrictions. Update the Go library to the latest version or apply the vendor's patch to enforce proper validation.

What to do
  • Update canonical golang-golang-x-net-dev to version 1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3.
  • Update canonical golang-golang-x-net-dev to version 1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3.
  • Update x golang.org/x/net to version 0.55.0.
  • Update x rootio-golang.org/x/net to version v0.52.0-root.io.1.
  • Update x golang.org/x/net to version v0.52.0-aikido.1.
  • Update x rootio-golang.org/x/net to version v0.39.0-root.io.2.
  • Update x golang.org/x/net to version v0.39.0-aikido.2.
  • Update x rootio-golang.org/x/net to version v0.35.0-root.io.1.
  • Update x golang.org/x/net to version v0.35.0-aikido.1.
  • Update x rootio-golang.org/x/net to version v0.42.0-root.io.2.
  • Update x golang.org/x/net to version v0.42.0-aikido.2.
  • Update x golang.org/x/net to version v0.34.0-aikido.2.
  • Update x rootio-golang.org/x/net to version v0.34.0-root.io.2.
  • Update stdlib to version 1.27.0-rc.3.
  • Update debian golang-golang-x-net to version 1:0.55.0-1.
  • Update x golang.org/x/net to version v0.37.0-aikido.1.
  • Update x rootio-golang.org/x/net to version v0.37.0-root.io.1.
  • Update x golang.org/x/net to version v0.47.0-aikido.2.
  • Update x rootio-golang.org/x/net to version v0.47.0-root.io.2.
  • Update golang net to version 0.55.0 or later.
  • Update golang.org/x/net golang.org/x/net/idna to version 0.55.0 or later.
  • Update go standard library net/http to version 1.25.13 or later.
  • Update go standard library net/http/internal/http2 to version 1.25.13 or later.
Affected software
Ecosystem VendorProductAffected versions
– golang net < 0.55.0
cpe:2.3:a:golang:net:*:*:*:*:*:go:*:*
– golang.org/x/net golang.org/x/net/idna < 0.55.0
Ubuntu:Pro:18.04:LTS canonical golang-golang-x-net-dev < 1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3
Fix: upgrade to 1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3
Ubuntu:Pro:20.04:LTS canonical golang-golang-x-net-dev < 1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3
Fix: upgrade to 1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3
Debian:11 debian golang-golang-x-net All versions
Debian:12 debian golang-golang-x-net All versions
Debian:13 debian golang-golang-x-net All versions
Debian:14 debian golang-golang-x-net < 1:0.55.0-1
Fix: upgrade to 1:0.55.0-1
Go x golang.org/x/net < 0.55.0
Fix: upgrade to 0.55.0
Root:Go x rootio-golang.org/x/net < v0.52.0-root.io.1
< v0.39.0-root.io.2
< v0.35.0-root.io.1
< v0.42.0-root.io.2
< v0.34.0-root.io.2
< v0.37.0-root.io.1
< v0.47.0-root.io.2
Fix: upgrade to v0.52.0-root.io.1
Root:Go x golang.org/x/net < v0.52.0-aikido.1
< v0.39.0-aikido.2
< v0.35.0-aikido.1
< v0.42.0-aikido.2
< v0.34.0-aikido.2
< v0.37.0-aikido.1
< v0.47.0-aikido.2
Fix: upgrade to v0.52.0-aikido.1
– go standard library net/http < 1.25.13
– go standard library net/http/internal/http2 < 1.25.13
Go – stdlib >= 1.27.0-0, < 1.27.0-rc.3
Fix: upgrade to 1.27.0-rc.3
Ubuntu:Pro:16.04:LTS canonical juju-core All versions
Ubuntu:Pro:16.04:LTS canonical lxd All versions
Ubuntu:Pro:16.04:LTS canonical containerd All versions
Ubuntu:Pro:16.04:LTS canonical google-guest-agent All versions
Ubuntu:Pro:20.04:LTS canonical adsys All versions
Ubuntu:Pro:22.04:LTS canonical golang-golang-x-net All versions
Ubuntu:20.04:LTS canonical golang-1.21 All versions
Ubuntu:14.04:LTS canonical golang-1.10 All versions
Ubuntu:16.04:LTS canonical golang-1.6 All versions
Ubuntu:Pro:16.04:LTS canonical golang-1.13 All versions
Ubuntu:Pro:16.04:LTS canonical golang-1.18 All versions
Ubuntu:Pro:16.04:LTS canonical google-osconfig-agent All versions
Ubuntu:Pro:18.04:LTS canonical golang-1.16 All versions
Ubuntu:18.04:LTS canonical golang-1.8 All versions
Ubuntu:18.04:LTS canonical golang-1.9 All versions
Ubuntu:20.04:LTS canonical golang-1.14 All versions
Ubuntu:20.04:LTS canonical golang-1.20 All versions
Ubuntu:20.04:LTS canonical golang-1.22 All versions
Ubuntu:22.04:LTS canonical golang-1.17 All versions
Ubuntu:22.04:LTS canonical golang-1.23 All versions
Ubuntu:22.04:LTS canonical golang-1.24 All versions
Ubuntu:26.04:LTS canonical golang-1.25 All versions
Ubuntu:26.04:LTS canonical golang-1.26 All versions
Original advisory text
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
References
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.2 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-1289Improper Validation of Unsafe Equivalence in Input
Timeline
Published22 May 2026
Updated3 Oct 2026
First seen3 Jun 2026
Track software like this
Free during beta