CVE-2026-25679Patch(golang / go)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-425CWE-1286

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-07); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
go

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-03-06: 1Mentions · 2026-03-07: 2Mentions · 2026-03-09: 2Mentions · 2026-03-20: 1Mentions · 2026-06-26: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-03-07: 2Technical Details · 2026-03-09: 203-0603-0703-0903-2006-26
Signal classification3 categories
Patch
342.9%
Disclosure
342.9%
General
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-061
Patch1
2026-03-072
Disclosure2
2026-03-092
Disclosure1Patch1
2026-03-201
General1
2026-06-261
Patch1
Full discourse7 posts
  • Go@golang
    Patch

    🌟 Go 1.26.1 and 1.25.8 are released! 🔐 Security: Includes security fixes for the standard library (CVE-2026-25679, CVE-2026-27137, CVE-2026-27138, CVE-2026-27139, CVE-2026-27142). 🗣 Announcement: https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk/m/41DopX_WAAAJ ⬇️ Download: https://go.dev/dl/#go1.26.1 #golang https://t.co/20adn9vysT

    Post summary

    Go 1.26.1 (and 1.25.8) released with security fixes for several CVEs, offering a patch to address the vulnerabilities.

    511196015260.9K
    207.1K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🔒 ELSA-2026-29702: Atualização IMPORTANTE do runc no Oracle Linux 9 corrige 3 CVEs (CVE-2026-25679, CVE-2026-32280, CVE-2026-32281). Saiba mais: -> http://tinyurl.com/ub67wkx3 #Oracle https://t.co/WLfmq1SbNR

    Post summary

    The tweet informs users that an important update to runc on Oracle Linux 9 addresses three CVEs, offering a link for more information.

    1001086
    1.5K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Go CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped CVE-2026-25679: net/url: reject IPv6 literal not at start of host CVE-2026-27139: os: FileInfo can escape from a Root

    Post summary

    The message announces three new Go language CVEs, describing specific template, URL parsing, and file system issues, with no evidence of PoC, exploit, patch, or active misuse.

    00010241
    4.4K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2026-25679 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/435 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The post notes that CVE-2026-25679 is no longer present in the latest AWS Lambda base image scans, but provides no further details on exploitation, mitigation, or technical characteristics.

    0000027
    31 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🔒 Urgent: #openSUSE Tumbleweed patches 3 critical Go vulns (CVE-2026-25679, CVE-2026-27139, CVE-2026-27142). Update go1.25 to 1.25.8-1.1 now to mitigate crypto bypass, path traversal & HTTP DoS attacks. Read more: 👉 https://tinyurl.com/ym2ahjs8 #Security https://t.co/PLdX24JVrj

    Post summary

    The tweet announces that openSUSE Tumbleweed has applied patches for three critical Go vulnerabilities, advising users to update to go1.25.8‑1.1 to protect against crypto bypass, path traversal, and HTTP DoS attacks.

    0000059
    1.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25679 url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. https://www.cve.org/CVERecord?id=CVE-2026-25679

    Post summary

    The text provides a brief technical description of CVE-2026-25679 as a URL parsing flaw that accepts invalid URLs, alongside a link to the official CVE record.

    00000100
    56.6K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2026-25679 impacts stdlib in 27 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/435 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A newly identified CVE-2026-25679 affecting the standard library of 27 AWS Lambda base images has been reported, with details posted on GitHub and the Lambdawatchdog website.

    0000035
    31 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---
Appgolanggo1.26.0--

Explore more