Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89363.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-89363
Upstream
  • CVE-2026-42507
Published
2026-06-02T23:16:38Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-42507 affecting package golang for versions less than 1.25.11-1
Details

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

References

Affected packages

Azure Linux:3 / golang

Package

Name
golang
Purl
pkg:rpm/azure-linux/golang

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.25.11-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89363.json"