{"id":"AZL-87798","summary":"CVE-2026-39821 affecting package golang for versions less than 1.26.4-3","details":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".","modified":"2026-08-29T05:27:27Z","published":"2026-05-22T16:16:20Z","upstream":["CVE-2026-39821"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821"}],"affected":[{"package":{"name":"golang","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/golang"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.26.0"},{"fixed":"1.26.4-3"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-87798.json"}}],"schema_version":"1.9.0"}