Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Release golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7 ALSA-2026:22112

Open
#3,379 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
20/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Active
Tech stack
go
Domain
release, security

Research direction

No source files, tests, or entry points are named. Start by reviewing the listed CVEs and affected Go Toolset packages; the payload does not specify a code change, validation target, or other definition of done.

Written by the indexing model from the issue text.

Description

go-toolset:rhel8 security update
Severity: Important
Description
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.

Security Fix(es):

  • net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
  • cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy (CVE-2026-42501)
  • html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content (CVE-2026-39823)
  • cmd/go: golang: Go 'go bug' command: Arbitrary file overwrite via symlink attack (CVE-2026-39819)
  • net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814)
  • net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)
  • net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
  • net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (CVE-2026-39825)
  • cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction (CVE-2026-39817)
  • html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping (CVE-2026-39826)
  • net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows (CVE-2026-39836)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected packages:
golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-misc-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-src-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-tests-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
delve-1.25.2-1.module+el8.10.0+23746+9db33b5e.x86_64
go-toolset-1.25.10-1.module+el8.10.0+24308+5c4a16b7.x86_64
golang-1.25.10-1.module+el8.10.0+24308+5c4a16b7.x86_64
golang-bin-1.25.10-1.module+el8.10.0+24308+5c4a16b7.x86_64
golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-misc-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-race-1.25.10-1.module+el8.10.0+24308+5c4a16b7.x86_64
golang-src-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-tests-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-misc-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-src-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-tests-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-misc-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-src-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-tests-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-misc-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-src-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-tests-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
go-toolset-1.25.10-1.module+el8.10.0+24308+5c4a16b7.s390x
golang-1.25.10-1.module+el8.10.0+24308+5c4a16b7.s390x
golang-bin-1.25.10-1.module+el8.10.0+24308+5c4a16b7.s390x
golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-misc-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-race-1.25.10-1.module+el8.10.0+24308+5c4a16b7.s390x
golang-src-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-tests-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-misc-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-src-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-tests-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-misc-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-src-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-tests-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
delve-1.25.2-1.module+el8.10.0+23746+9db33b5e.ppc64le
go-toolset-1.25.10-1.module+el8.10.0+24308+5c4a16b7.ppc64le
golang-1.25.10-1.module+el8.10.0+24308+5c4a16b7.ppc64le
golang-bin-1.25.10-1.module+el8.10.0+24308+5c4a16b7.ppc64le
golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-misc-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-race-1.25.10-1.module+el8.10.0+24308+5c4a16b7.ppc64le
golang-src-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-tests-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-misc-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-src-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-tests-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-misc-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-src-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-tests-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-misc-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-src-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-tests-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
delve-1.25.2-1.module+el8.10.0+23746+9db33b5e.aarch64
go-toolset-1.25.10-1.module+el8.10.0+24308+5c4a16b7.aarch64
golang-1.25.10-1.module+el8.10.0+24308+5c4a16b7.aarch64
golang-bin-1.25.10-1.module+el8.10.0+24308+5c4a16b7.aarch64
golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-misc-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-race-1.25.10-1.module+el8.10.0+24308+5c4a16b7.aarch64
golang-src-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-tests-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-misc-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-src-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-tests-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-misc-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-src-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-tests-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-docs-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-misc-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-src-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch
golang-tests-1.25.10-1.module+el8.10.0+24308+5c4a16b7.noarch

Dominant language
No language data
Stars
2
Forks
0
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from AlmaLinux/updates

All issues in AlmaLinux/updates

Similar issues

More Release issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.