{"id":"UBUNTU-CVE-2026-39821","details":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".","modified":"2026-06-30T18:17:59.933551597Z","published":"2026-05-22T16:16:00Z","related":["USN-8416-1"],"upstream":["CVE-2026-39821"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-39821"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-39821"},{"type":"REPORT","url":"https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"},{"type":"REPORT","url":"https://github.com/golang/go/issues/78760"},{"type":"REPORT","url":"https://go.dev/cl/767220"},{"type":"REPORT","url":"https://go.dev/issue/78760"},{"type":"REPORT","url":"https://pkg.go.dev/vuln/GO-2026-5026"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8416-1"}],"affected":[{"package":{"name":"golang-golang-x-net-dev","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/golang-golang-x-net-dev?arch=source&distro=esm-apps%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3"}]}],"versions":["1:0.0+git20170629.c81e7f2+dfsg-1ubuntu1","1:0.0+git20170629.c81e7f2+dfsg-1ubuntu2","1:0.0+git20170629.c81e7f2+dfsg-2","1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm1","1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm2"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"golang-go.net-dev","binary_version":"1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3"},{"binary_name":"golang-golang-x-net-dev","binary_version":"1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-golang-x-net-dev","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/golang-golang-x-net-dev?arch=source&distro=esm-apps%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3"}]}],"versions":["1:0.0+git20190811.74dc4d7+dfsg-1","1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm1","1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm2"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_version":"1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3","binary_name":"golang-go.net-dev"},{"binary_name":"golang-golang-x-net-dev","binary_version":"1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"},{"type":"Ubuntu","score":"medium"}]}