[NEW] [high] Golang Go: Multiple vulnerabilities
A remote, anonymous attacker can exploit multiple vulnerabilities in Golang Go to cause a denial of service, perform cross site scripting, bypass security measures or manipulate data.
CSIRTS triage
- What
- Multiple vulnerabilities in Golang Go allow remote denial of service, cross-site scripting, security bypass, and data manipulation.
- Who is affected
- Go applications and systems running vulnerable Go versions are exposed to remote anonymous attackers.
- Urgency
- High; remote attackers can cause denial of service and bypass security controls without authentication.
- Action
- Upgrade Golang Go to the latest patched release addressing CVE-2026-33818, CVE-2026-39821, and related CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Go
Get an email when a new Go advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2850
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-338180.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-398210.66% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-466000.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-568530.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-568580.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-568590.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-568600.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-568620.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-568640.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-568650.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-33818 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-39821 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46600 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56853 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56858 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56859 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56860 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56862 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56864 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56865 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] Golang Go-Module (Net, Image, Crypto): Multiple Vulnerabilitiescert-bund
- highCVE-2026-56865: A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a r…nvd
- highCVE-2026-56864: A malicious GOSUMDB was capable of serving arbitrary module content not contained within the t…nvd
- highCVE-2026-56862: Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of…nvd
- mediumCVE-2026-56860: Previously, resolving relative paths containing parent directory ('..') segments performed str…nvd
- highCVE-2026-56859: Previously, DecodeElement would reset the depth counter causing it to never fire; this could l…nvd
- mediumCVE-2026-56858: Previously, pathological inputs could close an unescaped '/' early, allowing for attack-contro…nvd
- highCVE-2026-56853: When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new …nvd
- highCVE-2026-33818: Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested,…nvd
- high[NEW] [high] Oracle Solaris third-party components: Multiple vulnerabilitiescert-bund
- highCVE-2026-46600: Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessagemsrc
- unknownMultiple vulnerabilities in IBM products (July 31, 2026)cert-fr-avis
Recent advisories for Golang Go
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] Golang Go: Multiple vulnerabilities allow information disclosurecert-bund · 2026-08-14
- high[UPDATE] [high] Golang Go: Multiple vulnerabilitiescert-bund · 2026-08-14
- medium[UPDATE] [medium] Golang Go-Module (Net, Image, Crypto): Multiple Vulnerabilitiescert-bund · 2026-08-14
- medium[UPDATE] [medium] Golang Go: Multiple vulnerabilitiescert-bund · 2026-08-14
- high[UPDATE] [high] Golang Go: Multiple vulnerabilitiescert-bund · 2026-08-14
- high[UPDATE] [high] Golang Go: Multiple vulnerabilities allow unspecified attackcert-bund · 2026-08-14
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] GStreamer: Multiple Vulnerabilities2026-08-17
- medium[NEW] [medium] Apache Struts: Multiple vulnerabilities2026-08-17
- high[NEW] [high] PostgreSQL: Multiple vulnerabilities2026-08-17
- high[UPDATE] [high] Oracle PeopleSoft: Multiple Vulnerabilities2026-08-17
- critical[NEW] [high] SAP Patch Day August 2026: Multiple vulnerabilities2026-08-17