{"id":"CVE-2026-39821","summary":"Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna","details":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".","aliases":["GO-2026-5026"],"modified":"2026-08-01T03:32:47.593636847Z","published":"2026-05-22T15:01:21.462Z","related":["ALSA-2026:30853","ALSA-2026:30854","ALSA-2026:30855","ALSA-2026:34357","ALSA-2026:34359","ALSA-2026:35826","ALSA-2026:35827","ALSA-2026:35828","ALSA-2026:35829","ALSA-2026:35830","ALSA-2026:35831","ALSA-2026:37435","ALSA-2026:37436","ALSA-2026:38995","ALSA-2026:39573","ALSA-2026:46395","CGA-frmm-xgw5-xmhr","SUSE-OU-2016:2857-1","SUSE-SU-2026:22066-1","SUSE-SU-2026:22075-1","SUSE-SU-2026:22157-1","SUSE-SU-2026:22159-1","SUSE-SU-2026:22193-1","SUSE-SU-2026:22226-1","SUSE-SU-2026:22233-1","SUSE-SU-2026:22242-1","SUSE-SU-2026:22249-1","SUSE-SU-2026:22285-1","SUSE-SU-2026:22305-1","SUSE-SU-2026:22320-1","SUSE-SU-2026:22328-1","SUSE-SU-2026:22367-1","SUSE-SU-2026:22376-1","SUSE-SU-2026:22423-1","SUSE-SU-2026:22424-1","SUSE-SU-2026:22432-1","SUSE-SU-2026:22442-1","SUSE-SU-2026:22443-1","SUSE-SU-2026:22455-1","SUSE-SU-2026:22456-1","SUSE-SU-2026:22513-1","SUSE-SU-2026:22546-1","SUSE-SU-2026:22558-1","SUSE-SU-2026:22567-1","SUSE-SU-2026:22575-1","SUSE-SU-2026:22703-1","SUSE-SU-2026:22800-1","SUSE-SU-2026:22848-1","SUSE-SU-2026:2285-1","SUSE-SU-2026:22855-1","SUSE-SU-2026:22887-1","SUSE-SU-2026:22892-1","SUSE-SU-2026:22934-1","SUSE-SU-2026:22945-1","SUSE-SU-2026:22952-1","SUSE-SU-2026:2466-1","SUSE-SU-2026:2467-1","SUSE-SU-2026:2468-1","SUSE-SU-2026:2581-1","SUSE-SU-2026:2609-1","SUSE-SU-2026:2611-1","SUSE-SU-2026:2612-1","SUSE-SU-2026:2639-1","SUSE-SU-2026:2640-1","SUSE-SU-2026:2643-1","SUSE-SU-2026:2665-1","SUSE-SU-2026:2682-1","SUSE-SU-2026:2683-1","SUSE-SU-2026:2692-1","SUSE-SU-2026:2706-1","SUSE-SU-2026:2733-1","SUSE-SU-2026:2768-1","SUSE-SU-2026:2774-1","SUSE-SU-2026:2823-1","SUSE-SU-2026:2824-1","SUSE-SU-2026:2830-1","SUSE-SU-2026:3056-1","SUSE-SU-2026:3057-1","SUSE-SU-2026:3197-1","SUSE-SU-2026:3198-1","SUSE-SU-2026:3203-1","SUSE-SU-2026:3209-1","SUSE-SU-2026:3210-1","SUSE-SU-2026:3265-1","SUSE-SU-2026:3266-1","SUSE-SU-2026:3267-1","SUSE-SU-2026:3300-1","SUSE-SU-2026:3327-1","SUSE-SU-2026:3342-1","SUSE-SU-2026:3416-1","SUSE-SU-2026:3417-1","SUSE-SU-2026:3421-1","SUSE-SU-2026:3432-1","openSUSE-SU-2026:10856-1","openSUSE-SU-2026:10871-1","openSUSE-SU-2026:10872-1","openSUSE-SU-2026:10873-1","openSUSE-SU-2026:10875-1","openSUSE-SU-2026:10876-1","openSUSE-SU-2026:10877-1","openSUSE-SU-2026:10886-1","openSUSE-SU-2026:10887-1","openSUSE-SU-2026:10889-1","openSUSE-SU-2026:10899-1","openSUSE-SU-2026:10901-1","openSUSE-SU-2026:10908-1","openSUSE-SU-2026:10913-1","openSUSE-SU-2026:10921-1","openSUSE-SU-2026:10930-1","openSUSE-SU-2026:10971-1","openSUSE-SU-2026:10981-1","openSUSE-SU-2026:10997-1","openSUSE-SU-2026:11011-1","openSUSE-SU-2026:11012-1","openSUSE-SU-2026:11050-1","openSUSE-SU-2026:11053-1","openSUSE-SU-2026:11075-1","openSUSE-SU-2026:11107-1","openSUSE-SU-2026:11126-1","openSUSE-SU-2026:11144-1","openSUSE-SU-2026:11153-1","openSUSE-SU-2026:11199-1","openSUSE-SU-2026:11290-1","openSUSE-SU-2026:11305-1","openSUSE-SU-2026:11314-1","openSUSE-SU-2026:11330-1","openSUSE-SU-2026:11331-1","openSUSE-SU-2026:11340-1","openSUSE-SU-2026:11376-1","openSUSE-SU-2026:20853-1","openSUSE-SU-2026:20854-1","openSUSE-SU-2026:20888-1","openSUSE-SU-2026:20892-1","openSUSE-SU-2026:20893-1","openSUSE-SU-2026:20902-1","openSUSE-SU-2026:20940-1","openSUSE-SU-2026:20956-1","openSUSE-SU-2026:20994-1","openSUSE-SU-2026:21010-1","openSUSE-SU-2026:21013-1","openSUSE-SU-2026:21060-1","openSUSE-SU-2026:21069-1","openSUSE-SU-2026:21079-1","openSUSE-SU-2026:21084-1","openSUSE-SU-2026:21120-1","openSUSE-SU-2026:21151-1","openSUSE-SU-2026:21157-1","openSUSE-SU-2026:21205-1","openSUSE-SU-2026:21210-1","openSUSE-SU-2026:21213-1","openSUSE-SU-2026:21241-1","openSUSE-SU-2026:21247-1","openSUSE-SU-2026:21251-1","openSUSE-SU-2026:21265-1","openSUSE-SU-2026:21277-1","openSUSE-SU-2026:21379-1","openSUSE-SU-2026:21395-1","openSUSE-SU-2026:21413-1","openSUSE-SU-2026:21422-1","openSUSE-SU-2026:21433-1","openSUSE-SU-2026:21436-1","openSUSE-SU-2026:21441-1","openSUSE-SU-2026:21456-1","openSUSE-SU-2026:21476-1","openSUSE-SU-2026:21480-1","openSUSE-SU-2026:21482-1","openSUSE-SU-2026:21483-1","openSUSE-SU-2026:21494-1","openSUSE-SU-2026:21499-1","openSUSE-SU-2026:21500-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"0.55.0"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"Go","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39821.json"},"references":[{"type":"WEB","url":"https://go.dev/cl/767220"},{"type":"WEB","url":"https://go.dev/issue/78760"},{"type":"WEB","url":"https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"},{"type":"WEB","url":"https://pkg.go.dev"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2026-5026"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:23262"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:23264"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:26546"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:26547"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30650"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30651"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30853"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30854"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30855"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33155"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33160"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33163"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33173"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33183"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33524"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33531"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34342"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34357"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34359"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34364"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34789"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:35826"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:35827"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:35828"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:35829"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:35830"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:35831"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:35993"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:35994"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36105"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36167"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36207"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36648"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36651"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36796"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36797"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36808"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36820"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36883"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37387"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37435"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37436"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:38995"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:39005"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:39573"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:39879"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:40118"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:40262"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:40945"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:41019"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:41030"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:41031"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:41036"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:41055"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:41066"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:41928"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:41930"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42043"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42047"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42048"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42049"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42050"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42051"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42078"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42079"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42080"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42082"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42132"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42142"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42146"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42150"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42151"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42240"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42644"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42796"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42852"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:43038"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:43052"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:43692"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:44622"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:44624"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:46395"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:47149"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:47735"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:47737"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:47952"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-39821"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39821.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2480756"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/golang/net","events":[{"introduced":"0"},{"fixed":"7770ec48d03fec35e378665337b4faca93c38423"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.55.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:golang:net:*:*:*:*:*:go:*:*"}}],"versions":["v0.54.0","v0.41.0","v0.53.0","v0.52.0","v0.51.0","v0.50.0","v0.49.0","v0.48.0","v0.47.0","v0.46.0","v0.45.0","v0.44.0","v0.43.0","v0.42.0","v0.40.0","v0.39.0","v0.38.0","v0.37.0","v0.36.0","v0.35.0","v0.34.0","v0.33.0","v0.32.0","v0.31.0","v0.30.0","v0.29.0","v0.28.0","v0.27.0","v0.26.0","v0.25.0","v0.24.0","v0.23.0","v0.19.0","v0.22.0","v0.21.0","v0.20.0","v0.18.0","v0.17.0","v0.16.0","v0.15.0","v0.14.0","v0.13.0","v0.12.0","v0.11.0","v0.10.0","v0.9.0","v0.8.0","v0.7.0","v0.4.0","v0.6.0","v0.5.0","v0.3.0","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39821.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}