CVE-2026-39821: CWE-1289: Improper Validation of Unsafe Equivalence in Input in golang.org/x/net golang.org/x/net/idna
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
AI Analysis
Technical Summary
The vulnerability in golang.org/x/net/idna involves improper validation of unsafe equivalence in input, specifically in the ToASCII and ToUnicode functions. These functions incorrectly accept Punycode-encoded labels that decode to ASCII-only labels without error, allowing a mismatch between the ASCII hostname used for privilege checks and the Unicode hostname used later. This can lead to privilege escalation in applications relying on these functions for hostname validation. The CVSS v3.1 score is 9.6 (critical), reflecting network attack vector, low attack complexity, required privileges, no user interaction, scope change, and high confidentiality and integrity impact. Multiple Red Hat advisories reference this vulnerability, indicating it affects Red Hat Ansible Automation Platform and related products. However, no explicit patch or remediation level is stated in the provided data.
Potential Impact
The vulnerability allows attackers to bypass hostname-based privilege checks by exploiting the incorrect acceptance of certain Punycode-encoded labels. This can result in privilege escalation, where unauthorized users gain elevated access rights. The impact is high confidentiality and integrity compromise without denial of service. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Multiple Red Hat advisories reference this CVE, suggesting that fixes may be available in updated packages of Red Hat Ansible Automation Platform and related components. Users should monitor the linked Red Hat advisories for updates and apply security patches once released. Until patches are applied, avoid relying solely on ToASCII and ToUnicode functions from golang.org/x/net/idna for critical privilege checks involving hostnames.
CVE-2026-39821: CWE-1289: Improper Validation of Unsafe Equivalence in Input in golang.org/x/net golang.org/x/net/idna
Description
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
CVSS v3.1
Score 9.6critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in golang.org/x/net/idna involves improper validation of unsafe equivalence in input, specifically in the ToASCII and ToUnicode functions. These functions incorrectly accept Punycode-encoded labels that decode to ASCII-only labels without error, allowing a mismatch between the ASCII hostname used for privilege checks and the Unicode hostname used later. This can lead to privilege escalation in applications relying on these functions for hostname validation. The CVSS v3.1 score is 9.6 (critical), reflecting network attack vector, low attack complexity, required privileges, no user interaction, scope change, and high confidentiality and integrity impact. Multiple Red Hat advisories reference this vulnerability, indicating it affects Red Hat Ansible Automation Platform and related products. However, no explicit patch or remediation level is stated in the provided data.
Potential Impact
The vulnerability allows attackers to bypass hostname-based privilege checks by exploiting the incorrect acceptance of certain Punycode-encoded labels. This can result in privilege escalation, where unauthorized users gain elevated access rights. The impact is high confidentiality and integrity compromise without denial of service. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Multiple Red Hat advisories reference this CVE, suggesting that fixes may be available in updated packages of Red Hat Ansible Automation Platform and related components. Users should monitor the linked Red Hat advisories for updates and apply security patches once released. Until patches are applied, avoid relying solely on ToASCII and ToUnicode functions from golang.org/x/net/idna for critical privilege checks involving hostnames.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Go
- Date Reserved
- 2026-04-07T18:13:03.526Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-39821","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30855","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30853","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30854","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30651","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26547","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26546","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:23262","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:23264","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33155","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33160","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33163","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33173","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33183","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30650","vendor":"Red Hat"}]
Threat ID: 6a1079f0e1370fbb48159db0
Added to database: 05/22/2026, 15:44:48 UTC
Last enriched: 07/30/2026, 21:39:05 UTC
Last updated: 07/31/2026, 19:52:01 UTC
Views: 416
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.