{"id":"UBUNTU-CVE-2026-39821","details":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".","modified":"2026-10-02T17:30:05.085080762Z","published":"2026-05-22T16:16:00Z","related":["USN-8416-1"],"upstream":["CVE-2026-39821"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-39821"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-39821"},{"type":"REPORT","url":"https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"},{"type":"REPORT","url":"https://pkg.go.dev/vuln/GO-2026-5026"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8416-1"}],"affected":[{"package":{"name":"golang-1.10","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/golang-1.10?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.10.4-2ubuntu1~14.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-1.10","binary_version":"1.10.4-2ubuntu1~14.04.1"},{"binary_name":"golang-1.10-go","binary_version":"1.10.4-2ubuntu1~14.04.1"},{"binary_name":"golang-1.10-src","binary_version":"1.10.4-2ubuntu1~14.04.1"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.10","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/golang-1.10?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.10.4-2ubuntu1~16.04.1","1.10.4-2ubuntu1~16.04.2"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_name":"golang-1.10","binary_version":"1.10.4-2ubuntu1~16.04.2"},{"binary_name":"golang-1.10-go","binary_version":"1.10.4-2ubuntu1~16.04.2"},{"binary_name":"golang-1.10-src","binary_version":"1.10.4-2ubuntu1~16.04.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.6","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/golang-1.6?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.6-0ubuntu1","1.6-0ubuntu2","1.6-0ubuntu3","1.6-0ubuntu4","1.6-0ubuntu5","1.6.1-0ubuntu1","1.6.2-0ubuntu5~16.04","1.6.2-0ubuntu5~16.04.2","1.6.2-0ubuntu5~16.04.3","1.6.2-0ubuntu5~16.04.4"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_name":"golang-1.6","binary_version":"1.6.2-0ubuntu5~16.04.4"},{"binary_name":"golang-1.6-go","binary_version":"1.6.2-0ubuntu5~16.04.4"},{"binary_name":"golang-1.6-src","binary_version":"1.6.2-0ubuntu5~16.04.4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"juju-core","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/juju-core?arch=source&distro=esm-infra%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.24.6-0ubuntu3","1.25.0-0ubuntu1","1.25.0-0ubuntu2","1.25.0-0ubuntu3","2.0~beta4-0ubuntu2","2.0~beta6-0ubuntu1.16.04.1","2.0~beta7-0ubuntu1.16.04.1","2.0~beta12-0ubuntu1.16.04.1","2.0~beta15-0ubuntu2.16.04.1","2.0.0-0ubuntu0.16.04.2","2.0.2-0ubuntu0.16.04.1","2.0.2-0ubuntu0.16.04.2","2.3.1-0ubuntu0.16.04.1","2.3.2-0ubuntu0.16.04.1","2.3.7-0ubuntu0.16.04.1","2.3.7-0ubuntu0.16.04.1+esm1","2.3.7-0ubuntu0.16.04.1+esm2"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_name":"juju","binary_version":"2.3.7-0ubuntu0.16.04.1+esm2"},{"binary_name":"juju-2.0","binary_version":"2.3.7-0ubuntu0.16.04.1+esm2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"lxd","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/lxd?arch=source&distro=esm-infra-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.20-0ubuntu4","0.21-0ubuntu3","0.21-0ubuntu5","0.22-0ubuntu1","0.22-0ubuntu2","0.23-0ubuntu1","0.23-0ubuntu2","0.23-0ubuntu3","0.24-0ubuntu2","0.24-0ubuntu3","0.24-0ubuntu4","0.25-0ubuntu1","0.26-0ubuntu2","0.26-0ubuntu3","0.27-0ubuntu1","0.27-0ubuntu2","2.0.0~beta1-0ubuntu3","2.0.0~beta1-0ubuntu4","2.0.0~beta2-0ubuntu1","2.0.0~beta2-0ubuntu2","2.0.0~beta3-0ubuntu1","2.0.0~beta3-0ubuntu2","2.0.0~beta3-0ubuntu3","2.0.0~beta3-0ubuntu4","2.0.0~beta4-0ubuntu1","2.0.0~beta4-0ubuntu2","2.0.0~beta4-0ubuntu3","2.0.0~beta4-0ubuntu4","2.0.0~beta4-0ubuntu5","2.0.0~beta4-0ubuntu6","2.0.0~beta4-0ubuntu7","2.0.0~rc1-0ubuntu1","2.0.0~rc1-0ubuntu2","2.0.0~rc1-0ubuntu3","2.0.0~rc2-0ubuntu2","2.0.0~rc2-0ubuntu3","2.0.0~rc3-0ubuntu1","2.0.0~rc3-0ubuntu2","2.0.0~rc3-0ubuntu3","2.0.0~rc3-0ubuntu4","2.0.0~rc4-0ubuntu1","2.0.0~rc5-0ubuntu1","2.0.0~rc6-0ubuntu1","2.0.0~rc6-0ubuntu2","2.0.0~rc7-0ubuntu1","2.0.0~rc7-0ubuntu2","2.0.0~rc8-0ubuntu1","2.0.0~rc8-0ubuntu2","2.0.0~rc8-0ubuntu3","2.0.0~rc8-0ubuntu5","2.0.0~rc8-0ubuntu6","2.0.0~rc8-0ubuntu7","2.0.0~rc9-0ubuntu2","2.0.0~rc9-0ubuntu3","2.0.0~rc9-0ubuntu4","2.0.0~rc9-0ubuntu5","2.0.0-0ubuntu1","2.0.0-0ubuntu2","2.0.0-0ubuntu3","2.0.0-0ubuntu4","2.0.1-0ubuntu1~16.04.1","2.0.2-0ubuntu1~16.04.1","2.0.3-0ubuntu1~ubuntu16.04.2","2.0.4-0ubuntu1~ubuntu16.04.1","2.0.5-0ubuntu1~ubuntu16.04.1","2.0.8-0ubuntu1~ubuntu16.04.1","2.0.8-0ubuntu1~ubuntu16.04.2","2.0.9-0ubuntu1~16.04.1","2.0.9-0ubuntu1~16.04.2","2.0.10-0ubuntu1~16.04.1","2.0.10-0ubuntu1~16.04.2","2.0.11-0ubuntu1~16.04.2","2.0.11-0ubuntu1~16.04.4","2.0.11-0ubuntu1~16.04.4+esm1","2.0.11-0ubuntu1~16.04.4+esm2","2.0.11-0ubuntu1~16.04.4+esm3"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_name":"golang-github-lxc-lxd-dev","binary_version":"2.0.11-0ubuntu1~16.04.4+esm3"},{"binary_name":"lxc2","binary_version":"2.0.11-0ubuntu1~16.04.4+esm3"},{"binary_version":"2.0.11-0ubuntu1~16.04.4+esm3","binary_name":"lxd"},{"binary_version":"2.0.11-0ubuntu1~16.04.4+esm3","binary_name":"lxd-client"},{"binary_version":"2.0.11-0ubuntu1~16.04.4+esm3","binary_name":"lxd-tools"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"containerd","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/containerd?arch=source&distro=esm-apps-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.2.1-0ubuntu4~16.04","0.2.3-0ubuntu1~16.04","0.2.5-0ubuntu1~16.04.1","1.2.6-0ubuntu1~16.04.2","1.2.6-0ubuntu1~16.04.3","1.2.6-0ubuntu1~16.04.4","1.2.6-0ubuntu1~16.04.5","1.2.6-0ubuntu1~16.04.6","1.2.6-0ubuntu1~16.04.6+esm1","1.2.6-0ubuntu1~16.04.6+esm2","1.2.6-0ubuntu1~16.04.6+esm4","1.2.6-0ubuntu1~16.04.6+esm5","1.2.6-0ubuntu1~16.04.6+esm6","1.2.6-0ubuntu1~16.04.6+esm7"],"ecosystem_specific":{"binaries":[{"binary_name":"containerd","binary_version":"1.2.6-0ubuntu1~16.04.6+esm7"},{"binary_version":"1.2.6-0ubuntu1~16.04.6+esm7","binary_name":"golang-github-docker-containerd-dev"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.13","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/golang-1.13?arch=source&distro=esm-apps%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.13.8-1ubuntu1~16.04.2","1.13.8-1ubuntu1~16.04.3","1.13.8-1ubuntu1~16.04.3+esm2","1.13.8-1ubuntu1~16.04.3+esm3"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-1.13","binary_version":"1.13.8-1ubuntu1~16.04.3+esm3"},{"binary_name":"golang-1.13-go","binary_version":"1.13.8-1ubuntu1~16.04.3+esm3"},{"binary_version":"1.13.8-1ubuntu1~16.04.3+esm3","binary_name":"golang-1.13-src"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.18","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/golang-1.18?arch=source&distro=esm-apps%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.18.1-1ubuntu1~16.04.6","1.18.1-1ubuntu1~16.04.6+esm1"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_version":"1.18.1-1ubuntu1~16.04.6+esm1","binary_name":"golang-1.18"},{"binary_version":"1.18.1-1ubuntu1~16.04.6+esm1","binary_name":"golang-1.18-go"},{"binary_name":"golang-1.18-src","binary_version":"1.18.1-1ubuntu1~16.04.6+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"google-guest-agent","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/google-guest-agent?arch=source&distro=esm-apps-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20201217.02-0ubuntu1~16.04.0","20230426.00-0ubuntu2~16.04.3","20231004.02-0ubuntu1~16.04.1","20231004.02-0ubuntu1~16.04.2","20240716.00-0ubuntu1~16.04.0","20240716.00-0ubuntu1~16.04.0+esm1","20240716.00-0ubuntu1~16.04.0+esm2","20240716.00-0ubuntu1~16.04.0+esm3"],"ecosystem_specific":{"binaries":[{"binary_version":"20240716.00-0ubuntu1~16.04.0+esm3","binary_name":"google-guest-agent"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"google-osconfig-agent","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/google-osconfig-agent?arch=source&distro=esm-apps%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20210219.00-0ubuntu1~16.04.0","20230504.00-0ubuntu1~16.04.0","20240320.00-0ubuntu1~16.04.0","20240524.03-0ubuntu2~16.04.0","20251028.00-0ubuntu2~16.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"google-osconfig-agent","binary_version":"20251028.00-0ubuntu2~16.04.1"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.10","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/golang-1.10?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.10~rc1-1","1.10~rc1-1ubuntu1","1.10~rc1-2ubuntu1","1.10~rc2-1ubuntu1","1.10-1ubuntu1","1.10.1-1ubuntu2","1.10.4-2ubuntu1~18.04.1","1.10.4-2ubuntu1~18.04.2"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_name":"golang-1.10","binary_version":"1.10.4-2ubuntu1~18.04.2"},{"binary_version":"1.10.4-2ubuntu1~18.04.2","binary_name":"golang-1.10-go"},{"binary_name":"golang-1.10-src","binary_version":"1.10.4-2ubuntu1~18.04.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"lxd","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/lxd?arch=source&distro=esm-infra%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.18-0ubuntu6","2.19-0ubuntu1","2.20-0ubuntu3","2.20-0ubuntu4","2.21-0ubuntu1","2.21-0ubuntu2","2.21-0ubuntu3","2.21-0ubuntu4","3.0.0~beta2-0ubuntu3","3.0.0~beta3-0ubuntu3","3.0.0~beta5-0ubuntu2","3.0.0~beta7-0ubuntu1","3.0.0-0ubuntu1","3.0.0-0ubuntu2","3.0.0-0ubuntu3","3.0.0-0ubuntu4","3.0.1-0ubuntu1~18.04.1","3.0.2-0ubuntu1~18.04.1","3.0.3-0ubuntu1~18.04.1","3.0.3-0ubuntu1~18.04.2","3.0.3-0ubuntu1~18.04.2+esm1","3.0.3-0ubuntu1~18.04.2+esm2","3.0.3-0ubuntu1~18.04.2+esm3"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_name":"lxd","binary_version":"3.0.3-0ubuntu1~18.04.2+esm3"},{"binary_name":"lxd-client","binary_version":"3.0.3-0ubuntu1~18.04.2+esm3"},{"binary_name":"lxd-tools","binary_version":"3.0.3-0ubuntu1~18.04.2+esm3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"containerd","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/containerd?arch=source&distro=esm-apps%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.2.5-0ubuntu2","1.2.6-0ubuntu1~18.04.1","1.2.6-0ubuntu1~18.04.2","1.3.3-0ubuntu1~18.04.1","1.3.3-0ubuntu1~18.04.2","1.3.3-0ubuntu1~18.04.3","1.3.3-0ubuntu1~18.04.4","1.4.4-0ubuntu1~18.04.2","1.5.2-0ubuntu1~18.04.1","1.5.2-0ubuntu1~18.04.2","1.5.2-0ubuntu1~18.04.3","1.5.5-0ubuntu3~18.04.1","1.5.5-0ubuntu3~18.04.2","1.5.9-0ubuntu1~18.04.1","1.5.9-0ubuntu1~18.04.2","1.6.12-0ubuntu1~18.04.1","1.6.12-0ubuntu1~18.04.1+esm1","1.6.12-0ubuntu1~18.04.1+esm2","1.6.12-0ubuntu1~18.04.1+esm3","1.6.12-0ubuntu1~18.04.1+esm4"],"ecosystem_specific":{"binaries":[{"binary_name":"containerd","binary_version":"1.6.12-0ubuntu1~18.04.1+esm4"},{"binary_name":"golang-github-containerd-containerd-dev","binary_version":"1.6.12-0ubuntu1~18.04.1+esm4"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.13","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/golang-1.13?arch=source&distro=esm-apps%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.13.8-1ubuntu1~18.04.2","1.13.8-1ubuntu1~18.04.3","1.13.8-1ubuntu1~18.04.4","1.13.8-1ubuntu1~18.04.4+esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.13.8-1ubuntu1~18.04.4+esm1","binary_name":"golang-1.13"},{"binary_name":"golang-1.13-go","binary_version":"1.13.8-1ubuntu1~18.04.4+esm1"},{"binary_name":"golang-1.13-src","binary_version":"1.13.8-1ubuntu1~18.04.4+esm1"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.16","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/golang-1.16?arch=source&distro=esm-apps%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.16.2-0ubuntu1~18.04.2","1.16.2-0ubuntu1~18.04.2+esm1"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_version":"1.16.2-0ubuntu1~18.04.2+esm1","binary_name":"golang-1.16"},{"binary_version":"1.16.2-0ubuntu1~18.04.2+esm1","binary_name":"golang-1.16-go"},{"binary_name":"golang-1.16-src","binary_version":"1.16.2-0ubuntu1~18.04.2+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.18","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/golang-1.18?arch=source&distro=esm-apps%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.18.1-1ubuntu1~18.04.3","1.18.1-1ubuntu1~18.04.4","1.18.1-1ubuntu1~18.04.4+esm1"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_name":"golang-1.18","binary_version":"1.18.1-1ubuntu1~18.04.4+esm1"},{"binary_name":"golang-1.18-go","binary_version":"1.18.1-1ubuntu1~18.04.4+esm1"},{"binary_name":"golang-1.18-src","binary_version":"1.18.1-1ubuntu1~18.04.4+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.8","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/golang-1.8?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.8.3-2ubuntu1","1.8.3-2ubuntu1.18.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-1.8","binary_version":"1.8.3-2ubuntu1.18.04.1"},{"binary_name":"golang-1.8-go","binary_version":"1.8.3-2ubuntu1.18.04.1"},{"binary_name":"golang-1.8-go-shared-dev","binary_version":"1.8.3-2ubuntu1.18.04.1"},{"binary_version":"1.8.3-2ubuntu1.18.04.1","binary_name":"golang-1.8-src"},{"binary_version":"1.8.3-2ubuntu1.18.04.1","binary_name":"libgolang-1.8-std1"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.9","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/golang-1.9?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.9.1-2ubuntu1","1.9.2-1ubuntu1","1.9.2-3ubuntu1","1.9.3-1ubuntu1","1.9.4-1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-1.9","binary_version":"1.9.4-1ubuntu1"},{"binary_name":"golang-1.9-go","binary_version":"1.9.4-1ubuntu1"},{"binary_name":"golang-1.9-src","binary_version":"1.9.4-1ubuntu1"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-golang-x-net-dev","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/golang-golang-x-net-dev?arch=source&distro=esm-apps%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3"}]}],"versions":["1:0.0+git20170629.c81e7f2+dfsg-1ubuntu1","1:0.0+git20170629.c81e7f2+dfsg-1ubuntu2","1:0.0+git20170629.c81e7f2+dfsg-2","1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm1","1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm2"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_name":"golang-go.net-dev","binary_version":"1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3"},{"binary_version":"1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3","binary_name":"golang-golang-x-net-dev"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"google-guest-agent","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/google-guest-agent?arch=source&distro=esm-apps%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20201217.02-0ubuntu1~18.04.0","20210414.00-0ubuntu1~18.04.0","20210629.00-0ubuntu1~18.04.1","20220622.00-0ubuntu2~18.04.0","20220622.00-0ubuntu2~18.04.1","20230426.00-0ubuntu2~18.04.0","20231004.02-0ubuntu1~18.04.2","20231004.02-0ubuntu1~18.04.3","20240716.00-0ubuntu1~18.04.0","20241011.01-0ubuntu1~18.04.0","20241011.01-0ubuntu1~18.04.0+esm1","20241011.01-0ubuntu1~18.04.0+esm2","20241011.01-0ubuntu1~18.04.0+esm3"],"ecosystem_specific":{"binaries":[{"binary_name":"google-guest-agent","binary_version":"20241011.01-0ubuntu1~18.04.0+esm3"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"google-osconfig-agent","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/google-osconfig-agent?arch=source&distro=esm-apps%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20210219.00-0ubuntu1~18.04.0","20210608.1-0ubuntu1~18.04.1","20210608.1-0ubuntu1~18.04.2","20220824.00-0ubuntu1~18.04.1","20230504.00-0ubuntu1~18.04.0","20240320.00-0ubuntu1~18.04.0","20240524.03-0ubuntu2~18.04.0","20240926.03-0ubuntu1~18.04.0","20251028.00-0ubuntu2~18.04.0"],"ecosystem_specific":{"binaries":[{"binary_name":"google-osconfig-agent","binary_version":"20251028.00-0ubuntu2~18.04.0"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"adsys","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/adsys?arch=source&distro=esm-infra%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.8~22.04","0.9.2~20.04","0.9.2~20.04.1","0.9.2~20.04.2","0.9.2~20.04.2ubuntu0.1","0.9.2~20.04.2ubuntu0.1+esm1","0.9.2~20.04.2ubuntu0.1+esm2"],"ecosystem_specific":{"binaries":[{"binary_name":"adsys","binary_version":"0.9.2~20.04.2ubuntu0.1+esm2"},{"binary_name":"adsys-windows","binary_version":"0.9.2~20.04.2ubuntu0.1+esm2"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"containerd","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/containerd?arch=source&distro=esm-infra%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.2.10-0ubuntu1","1.3.2-0ubuntu1","1.3.3-0ubuntu1","1.3.3-0ubuntu2","1.3.3-0ubuntu2.1","1.3.3-0ubuntu2.2","1.3.3-0ubuntu2.3","1.4.4-0ubuntu1~20.04.2","1.5.2-0ubuntu1~20.04.1","1.5.2-0ubuntu1~20.04.2","1.5.2-0ubuntu1~20.04.3","1.5.5-0ubuntu3~20.04.1","1.5.5-0ubuntu3~20.04.2","1.5.9-0ubuntu1~20.04.1","1.5.9-0ubuntu1~20.04.4","1.5.9-0ubuntu1~20.04.5","1.5.9-0ubuntu1~20.04.6","1.6.12-0ubuntu1~20.04.1","1.6.12-0ubuntu1~20.04.3","1.6.12-0ubuntu1~20.04.5","1.6.12-0ubuntu1~20.04.6","1.6.12-0ubuntu1~20.04.7","1.6.12-0ubuntu1~20.04.8","1.6.12-0ubuntu1~20.04.8+esm1","1.6.12-0ubuntu1~20.04.8+esm2"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-github-containerd-containerd-dev","binary_version":"1.6.12-0ubuntu1~20.04.8+esm2"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.13","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/golang-1.13?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.13.1-1ubuntu1","1.13.3-1ubuntu1","1.13.4-1ubuntu1","1.13.5-1ubuntu1","1.13.6-1ubuntu1","1.13.6-2ubuntu1","1.13.7-1ubuntu1","1.13.8-1ubuntu1","1.13.8-1ubuntu1.1","1.13.8-1ubuntu1.2"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-1.13","binary_version":"1.13.8-1ubuntu1.2"},{"binary_name":"golang-1.13-go","binary_version":"1.13.8-1ubuntu1.2"},{"binary_version":"1.13.8-1ubuntu1.2","binary_name":"golang-1.13-src"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.14","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/golang-1.14?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.14~beta1-1","1.14~beta1-2","1.14~rc1-1","1.14-1","1.14.1-1","1.14.2-1","1.14.2-1ubuntu1","1.14.3-2ubuntu2~20.04.1","1.14.3-2ubuntu2~20.04.2"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-1.14","binary_version":"1.14.3-2ubuntu2~20.04.2"},{"binary_name":"golang-1.14-go","binary_version":"1.14.3-2ubuntu2~20.04.2"},{"binary_name":"golang-1.14-src","binary_version":"1.14.3-2ubuntu2~20.04.2"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"google-guest-agent","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/google-guest-agent?arch=source&distro=esm-infra%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20201217.02-0ubuntu1~20.04.0","20210414.00-0ubuntu1~20.04.0","20210629.00-0ubuntu1~20.04.0","20220622.00-0ubuntu2~20.04.0","20220622.00-0ubuntu2~20.04.2","20230426.00-0ubuntu2~20.04.0","20231004.02-0ubuntu1~20.04.1","20231004.02-0ubuntu1~20.04.2","20231004.02-0ubuntu1~20.04.3","20231004.02-0ubuntu1~20.04.4","20240716.00-0ubuntu1~20.04.0","20241011.01-0ubuntu1~20.04.1","20250116.00-0ubuntu1~20.04.0","20250116.00-0ubuntu1~20.04.0+esm1","20250116.00-0ubuntu1~20.04.0+esm2","20250116.00-0ubuntu1~20.04.0+esm3"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_version":"20250116.00-0ubuntu1~20.04.0+esm3","binary_name":"google-guest-agent"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.16","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/golang-1.16?arch=source&distro=esm-apps%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.16.2-0ubuntu1~20.04","1.16.2-0ubuntu1~20.04.1","1.16.2-0ubuntu1~20.04.1+esm1"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_name":"golang-1.16","binary_version":"1.16.2-0ubuntu1~20.04.1+esm1"},{"binary_version":"1.16.2-0ubuntu1~20.04.1+esm1","binary_name":"golang-1.16-go"},{"binary_name":"golang-1.16-src","binary_version":"1.16.2-0ubuntu1~20.04.1+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.18","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/golang-1.18?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.18.1-1ubuntu1~20.04.1","1.18.1-1ubuntu1~20.04.2","1.18.1-1ubuntu1~20.04.3"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-1.18","binary_version":"1.18.1-1ubuntu1~20.04.3"},{"binary_version":"1.18.1-1ubuntu1~20.04.3","binary_name":"golang-1.18-go"},{"binary_version":"1.18.1-1ubuntu1~20.04.3","binary_name":"golang-1.18-src"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.20","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/golang-1.20?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.20.3-1ubuntu0.1~20.04","1.20.3-1ubuntu0.1~20.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-1.20","binary_version":"1.20.3-1ubuntu0.1~20.04.1"},{"binary_version":"1.20.3-1ubuntu0.1~20.04.1","binary_name":"golang-1.20-go"},{"binary_name":"golang-1.20-src","binary_version":"1.20.3-1ubuntu0.1~20.04.1"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.21","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/golang-1.21?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.21.1-1~ubuntu20.04.1","1.21.1-1~ubuntu20.04.2","1.21.1-1~ubuntu20.04.3"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-1.21","binary_version":"1.21.1-1~ubuntu20.04.3"},{"binary_name":"golang-1.21-go","binary_version":"1.21.1-1~ubuntu20.04.3"},{"binary_name":"golang-1.21-src","binary_version":"1.21.1-1~ubuntu20.04.3"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.22","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/golang-1.22?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.22.2-2~20.04.1","1.22.2-2~20.04.2"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_version":"1.22.2-2~20.04.2","binary_name":"golang-1.22"},{"binary_version":"1.22.2-2~20.04.2","binary_name":"golang-1.22-go"},{"binary_name":"golang-1.22-src","binary_version":"1.22.2-2~20.04.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-golang-x-net-dev","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/golang-golang-x-net-dev?arch=source&distro=esm-apps%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3"}]}],"versions":["1:0.0+git20190811.74dc4d7+dfsg-1","1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm1","1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm2"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-go.net-dev","binary_version":"1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3"},{"binary_name":"golang-golang-x-net-dev","binary_version":"1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"google-osconfig-agent","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/google-osconfig-agent?arch=source&distro=esm-infra%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20210219.00-0ubuntu1~20.04.0","20210608.1-0ubuntu1~20.04.0","20210608.1-0ubuntu1~20.04.1","20220824.00-0ubuntu1~20.04.1","20230504.00-0ubuntu1~20.04.0","20240320.00-0ubuntu1~20.04.0","20240320.00-0ubuntu1~20.04.1","20240524.03-0ubuntu2~20.04.0","20240926.03-0ubuntu1~20.04.0","20250115.01-0ubuntu1~20.04.0","20251028.00-0ubuntu2~20.04.0"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_name":"google-osconfig-agent","binary_version":"20251028.00-0ubuntu2~20.04.0"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"lxd","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/lxd?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:0.7","1:0.8","1:0.9","1:0.10"],"ecosystem_specific":{"binaries":[{"binary_name":"lxd","binary_version":"1:0.10"},{"binary_version":"1:0.10","binary_name":"lxd-client"},{"binary_name":"lxd-tools","binary_version":"1:0.10"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"adsys","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/adsys?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.7.1","0.7.1build1","0.8","0.8ubuntu1","0.8.1","0.8.2","0.8.3","0.8.4","0.8.5~22.04","0.9.2~22.04","0.9.2~22.04.1","0.9.2~22.04.2","0.14.1~22.04","0.14.2~22.04","0.14.2~22.04ubuntu0.1","0.14.3~22.04","0.14.3~22.04ubuntu0.1","0.16.3~22.04.1","0.16.3~22.04.2","0.16.3~22.04.2ubuntu0.22.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"adsys","binary_version":"0.16.3~22.04.2ubuntu0.22.04.1"},{"binary_name":"adsys-windows","binary_version":"0.16.3~22.04.2ubuntu0.22.04.1"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"containerd","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/containerd?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.5.5-0ubuntu3","1.5.9-0ubuntu1","1.5.9-0ubuntu2","1.5.9-0ubuntu3","1.5.9-0ubuntu3.1","1.6.12-0ubuntu1~22.04.1","1.6.12-0ubuntu1~22.04.3","1.6.12-0ubuntu1~22.04.5","1.6.12-0ubuntu1~22.04.6","1.6.12-0ubuntu1~22.04.7","1.6.12-0ubuntu1~22.04.8","1.6.12-0ubuntu1~22.04.9","1.6.12-0ubuntu1~22.04.10","1.6.12-0ubuntu1~22.04.11"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-github-containerd-containerd-dev","binary_version":"1.6.12-0ubuntu1~22.04.11"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.17","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/golang-1.17?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.17-1ubuntu2","1.17.3-1ubuntu1","1.17.3-1ubuntu2","1.17.13-3ubuntu1","1.17.13-3ubuntu1.2","1.17.13-3ubuntu1.3"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_name":"golang-1.17","binary_version":"1.17.13-3ubuntu1.3"},{"binary_version":"1.17.13-3ubuntu1.3","binary_name":"golang-1.17-go"},{"binary_name":"golang-1.17-src","binary_version":"1.17.13-3ubuntu1.3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.18","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/golang-1.18?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.18~beta1-0ubuntu1","1.18~beta2-1ubuntu1","1.18~beta2-1ubuntu2","1.18~rc1-1ubuntu1","1.18-1ubuntu1","1.18.1-1ubuntu1","1.18.1-1ubuntu1.1","1.18.1-1ubuntu1.2"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-1.18","binary_version":"1.18.1-1ubuntu1.2"},{"binary_name":"golang-1.18-go","binary_version":"1.18.1-1ubuntu1.2"},{"binary_version":"1.18.1-1ubuntu1.2","binary_name":"golang-1.18-src"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.20","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/golang-1.20?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.20.3-1ubuntu0.1~22.04","1.20.3-1ubuntu0.1~22.04.1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.20.3-1ubuntu0.1~22.04.1","binary_name":"golang-1.20"},{"binary_name":"golang-1.20-go","binary_version":"1.20.3-1ubuntu0.1~22.04.1"},{"binary_name":"golang-1.20-src","binary_version":"1.20.3-1ubuntu0.1~22.04.1"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.21","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/golang-1.21?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.21.1-1~ubuntu22.04.1","1.21.1-1~ubuntu22.04.2","1.21.1-1~ubuntu22.04.3"],"ecosystem_specific":{"binaries":[{"binary_version":"1.21.1-1~ubuntu22.04.3","binary_name":"golang-1.21"},{"binary_name":"golang-1.21-go","binary_version":"1.21.1-1~ubuntu22.04.3"},{"binary_version":"1.21.1-1~ubuntu22.04.3","binary_name":"golang-1.21-src"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.22","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/golang-1.22?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.22.2-2~22.04","1.22.2-2~22.04.1","1.22.2-2~22.04.2","1.22.2-2~22.04.3"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_version":"1.22.2-2~22.04.3","binary_name":"golang-1.22"},{"binary_name":"golang-1.22-go","binary_version":"1.22.2-2~22.04.3"},{"binary_name":"golang-1.22-src","binary_version":"1.22.2-2~22.04.3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.23","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/golang-1.23?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.23.1-1~22.04","1.23.1-1~22.04.2"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_name":"golang-1.23","binary_version":"1.23.1-1~22.04.2"},{"binary_name":"golang-1.23-go","binary_version":"1.23.1-1~22.04.2"},{"binary_version":"1.23.1-1~22.04.2","binary_name":"golang-1.23-src"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.24","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/golang-1.24?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.24.4-1ubuntu1~22.04.1","1.24.4-1ubuntu1~22.04.2","1.24.13-2~22.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-1.24","binary_version":"1.24.13-2~22.04.1"},{"binary_version":"1.24.13-2~22.04.1","binary_name":"golang-1.24-go"},{"binary_version":"1.24.13-2~22.04.1","binary_name":"golang-1.24-src"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"google-guest-agent","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/google-guest-agent?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20210629.00-0ubuntu1","20210629.00-0ubuntu2","20220104.00-0ubuntu1","20220104.00-0ubuntu2","20220622.00-0ubuntu2~22.04.0","20220622.00-0ubuntu2~22.04.1","20230426.00-0ubuntu2~22.04.0","20231004.02-0ubuntu1~22.04.1","20231004.02-0ubuntu1~22.04.2","20231004.02-0ubuntu1~22.04.3","20231004.02-0ubuntu1~22.04.4","20231004.02-0ubuntu1~22.04.5","20240716.00-0ubuntu1~22.04.0","20241011.01-0ubuntu1~22.04.0","20250116.00-0ubuntu1~22.04.0","20250116.00-0ubuntu1~22.04.1","20250116.00-0ubuntu1~22.04.2","20250116.00-0ubuntu1~22.04.3"],"ecosystem_specific":{"binaries":[{"binary_name":"google-guest-agent","binary_version":"20250116.00-0ubuntu1~22.04.3"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"google-osconfig-agent","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/google-osconfig-agent?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20210608.1-0ubuntu1","20210608.1-0ubuntu2","20210608.1-0ubuntu3","20220824.00-0ubuntu1~22.04.1","20220824.00-0ubuntu1~22.04.2","20230504.00-0ubuntu1~22.04.0","20230504.00-0ubuntu1~22.04.1","20240320.00-0ubuntu1~22.04.0","20240320.00-0ubuntu1~22.04.1","20240524.03-0ubuntu2~22.04.0","20240524.03-0ubuntu2~22.04.1","20240926.03-0ubuntu1~22.04.0","20250115.01-0ubuntu1~22.04.0","20251028.00-0ubuntu2~22.04.0"],"ecosystem_specific":{"binaries":[{"binary_name":"google-osconfig-agent","binary_version":"20251028.00-0ubuntu2~22.04.0"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.13","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/golang-1.13?arch=source&distro=esm-apps%2Fjammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.13.8-1ubuntu2","1.13.8-1ubuntu2.22.04.1","1.13.8-1ubuntu2.22.04.1+esm1","1.13.8-1ubuntu2.22.04.2"],"ecosystem_specific":{"binaries":[{"binary_version":"1.13.8-1ubuntu2.22.04.2","binary_name":"golang-1.13"},{"binary_version":"1.13.8-1ubuntu2.22.04.2","binary_name":"golang-1.13-go"},{"binary_version":"1.13.8-1ubuntu2.22.04.2","binary_name":"golang-1.13-src"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-golang-x-net","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/golang-golang-x-net?arch=source&distro=esm-apps%2Fjammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:0.0+git20210119.5f4716e+dfsg-4","1:0.0+git20210805.aaa1db6+dfsg-1","1:0.0+git20211209.491a49a+dfsg-1","1:0.0+git20211209.491a49a+dfsg-1ubuntu0.1~esm1","1:0.0+git20211209.491a49a+dfsg-1ubuntu0.1~esm2"],"ecosystem_specific":{"binaries":[{"binary_version":"1:0.0+git20211209.491a49a+dfsg-1ubuntu0.1~esm2","binary_name":"golang-golang-x-net-dev"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"adsys","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/adsys?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.13.1","0.13.2","0.13.3","0.14.1","0.14.1build1","0.14.1ubuntu0.24.04.1","0.14.2~24.04","0.14.2~24.04ubuntu0.1","0.14.3~24.04","0.14.3~24.04ubuntu0.1","0.16.3~24.04.1","0.16.3~24.04.2","0.16.3~24.04.2ubuntu0.24.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"adsys","binary_version":"0.16.3~24.04.2ubuntu0.24.04.1"},{"binary_version":"0.16.3~24.04.2ubuntu0.24.04.1","binary_name":"adsys-windows"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.21","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/golang-1.21?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.21.1-1","1.21.3-1","1.21.4-1","1.21.5-1","1.21.6-1","1.21.7-1","1.21.7-2","1.21.8-1","1.21.8-1build1","1.21.9-1","1.21.9-1ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.21.9-1ubuntu0.1","binary_name":"golang-1.21"},{"binary_name":"golang-1.21-go","binary_version":"1.21.9-1ubuntu0.1"},{"binary_name":"golang-1.21-src","binary_version":"1.21.9-1ubuntu0.1"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.22","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/golang-1.22?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.22~rc1-2","1.22.0-1","1.22.0-2","1.22.1-1","1.22.1-1build1","1.22.2-2","1.22.2-2ubuntu0.1","1.22.2-2ubuntu0.2","1.22.2-2ubuntu0.3","1.22.2-2ubuntu0.4"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-1.22","binary_version":"1.22.2-2ubuntu0.4"},{"binary_name":"golang-1.22-go","binary_version":"1.22.2-2ubuntu0.4"},{"binary_name":"golang-1.22-src","binary_version":"1.22.2-2ubuntu0.4"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.23","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/golang-1.23?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.23.1-1~24.04","1.23.1-1~24.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-1.23","binary_version":"1.23.1-1~24.04.1"},{"binary_version":"1.23.1-1~24.04.1","binary_name":"golang-1.23-go"},{"binary_name":"golang-1.23-src","binary_version":"1.23.1-1~24.04.1"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.24","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/golang-1.24?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.24.4-1ubuntu1~24.04.1","1.24.4-1ubuntu1~24.04.2","1.24.13-2~24.04.1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.24.13-2~24.04.1","binary_name":"golang-1.24"},{"binary_name":"golang-1.24-go","binary_version":"1.24.13-2~24.04.1"},{"binary_name":"golang-1.24-src","binary_version":"1.24.13-2~24.04.1"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"google-guest-agent","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/google-guest-agent?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20230426.00-0ubuntu3","20231004.02-0ubuntu1","20231004.02-0ubuntu3","20240213.00-0ubuntu1","20240213.00-0ubuntu2","20240213.00-0ubuntu3","20240213.00-0ubuntu3.1","20240213.00-0ubuntu3.2","20240716.00-0ubuntu1~24.04.0","20240716.00-0ubuntu1~24.04.1","20241011.01-0ubuntu1~24.04.0","20250116.00-0ubuntu1~24.04.0","20250116.00-0ubuntu1~24.04.1","20250116.00-0ubuntu1~24.04.2","20250116.00-0ubuntu1~24.04.3","20250116.00-0ubuntu1~24.04.4"],"ecosystem_specific":{"binaries":[{"binary_version":"20250116.00-0ubuntu1~24.04.4","binary_name":"google-guest-agent"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"google-osconfig-agent","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/google-osconfig-agent?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20230504.00-0ubuntu2","20230504.00-0ubuntu3","20240320.00-0ubuntu1~24.04.0","20240320.00-0ubuntu1~24.04.1","20240320.00-0ubuntu1~24.04.2","20240524.03-0ubuntu2~24.04.0","20240524.03-0ubuntu2~24.04.1","20240926.03-0ubuntu1~24.04.0","20250115.01-0ubuntu1~24.04.0","20250115.01-0ubuntu1~24.04.1","20251028.00-0ubuntu2~24.04.0"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_name":"google-osconfig-agent","binary_version":"20251028.00-0ubuntu2~24.04.0"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"containerd","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/containerd?arch=source&distro=esm-apps%2Fnoble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.6.20~ds1-1ubuntu2","1.6.24~ds1-1ubuntu1","1.6.24~ds1-1ubuntu1.1","1.6.24~ds1-1ubuntu1.2","1.6.24~ds1-1ubuntu1.2+esm1","1.6.24~ds1-1ubuntu1.3","1.6.24~ds1-1ubuntu1.3+esm1","1.6.24~ds1-1ubuntu1.3+esm2","1.6.24~ds1-1ubuntu1.3+esm3"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-github-containerd-containerd-dev","binary_version":"1.6.24~ds1-1ubuntu1.3+esm3"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-golang-x-net","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/golang-golang-x-net?arch=source&distro=esm-apps%2Fnoble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:0.10.0-1","1:0.17.0+dfsg-1","1:0.20.0+dfsg-1","1:0.21.0+dfsg-1","1:0.21.0+dfsg-1ubuntu0.1~esm1","1:0.21.0+dfsg-1ubuntu0.1~esm2"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-golang-x-net-dev","binary_version":"1:0.21.0+dfsg-1ubuntu0.1~esm2"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"adsys","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/adsys?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.16.3","0.16.3ubuntu1","0.16.4","0.16.4ubuntu1","0.16.4ubuntu1.1"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_name":"adsys","binary_version":"0.16.4ubuntu1.1"},{"binary_version":"0.16.4ubuntu1.1","binary_name":"adsys-windows"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.23","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/golang-1.23?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.23.10-1"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-1.23","binary_version":"1.23.10-1"},{"binary_name":"golang-1.23-go","binary_version":"1.23.10-1"},{"binary_version":"1.23.10-1","binary_name":"golang-1.23-src"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.24","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/golang-1.24?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.24.4-1ubuntu1","1.24.9-1","1.24.13-2"],"ecosystem_specific":{"binaries":[{"binary_version":"1.24.13-2","binary_name":"golang-1.24"},{"binary_version":"1.24.13-2","binary_name":"golang-1.24-go"},{"binary_version":"1.24.13-2","binary_name":"golang-1.24-src"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.25","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/golang-1.25?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.25.0-0ubuntu1","1.25.7-2"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-1.25","binary_version":"1.25.7-2"},{"binary_name":"golang-1.25-go","binary_version":"1.25.7-2"},{"binary_name":"golang-1.25-src","binary_version":"1.25.7-2"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-1.26","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/golang-1.26?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.26~rc3-2","1.26.0-1"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-1.26","binary_version":"1.26.0-1"},{"binary_name":"golang-1.26-go","binary_version":"1.26.0-1"},{"binary_version":"1.26.0-1","binary_name":"golang-1.26-src"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"golang-golang-x-net","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/golang-golang-x-net?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:0.27.0-2"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-golang-x-net-dev","binary_version":"1:0.27.0-2"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"google-guest-agent","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/google-guest-agent?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20250506.01-0ubuntu1","20250506.01-0ubuntu2","20250506.01-0ubuntu2.1"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_version":"20250506.01-0ubuntu2.1","binary_name":"google-guest-agent"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"google-osconfig-agent","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/google-osconfig-agent?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20250701.00-0ubuntu1","20251028.00-0ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_version":"20251028.00-0ubuntu2","binary_name":"google-osconfig-agent"}],"priority_reason":"This is a critical issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}},{"package":{"name":"containerd","ecosystem":"Ubuntu:Pro:26.04:LTS","purl":"pkg:deb/ubuntu/containerd?arch=source&distro=esm-apps%2Fresolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.7.24~ds1-8ubuntu1","1.7.24~ds1-10ubuntu1","1.7.24~ds1-10ubuntu1+esm1"],"ecosystem_specific":{"priority_reason":"This is a critical issue","binaries":[{"binary_name":"golang-github-containerd-containerd-api-dev","binary_version":"1.7.24~ds1-10ubuntu1+esm1"},{"binary_version":"1.7.24~ds1-10ubuntu1+esm1","binary_name":"golang-github-containerd-containerd-dev"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-39821.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"},{"type":"Ubuntu","score":"high"}]}