Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.7%top 52%

CVE-2026-39821: CWE-1289: Improper Validation of Unsafe Equivalence in Input in golang.org/x/net golang.org/x/net/idna

0
Critical
VulnerabilityCVE-2026-39821cvecve-2026-39821cwe-1289
Published: 05/22/2026 (05/22/2026, 15:01:21 UTC)
Source: CVE Database V5
Vendor/Project: golang.org/x/net
Product: golang.org/x/net/idna

Description

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS v3.1

Score 9.6critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Affected software

golang.org/x/net/idna
pkg:golang/golang.org/x/net/idna
Affected versions
=0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 21:39:05 UTC

Technical Analysis

The vulnerability in golang.org/x/net/idna involves improper validation of unsafe equivalence in input, specifically in the ToASCII and ToUnicode functions. These functions incorrectly accept Punycode-encoded labels that decode to ASCII-only labels without error, allowing a mismatch between the ASCII hostname used for privilege checks and the Unicode hostname used later. This can lead to privilege escalation in applications relying on these functions for hostname validation. The CVSS v3.1 score is 9.6 (critical), reflecting network attack vector, low attack complexity, required privileges, no user interaction, scope change, and high confidentiality and integrity impact. Multiple Red Hat advisories reference this vulnerability, indicating it affects Red Hat Ansible Automation Platform and related products. However, no explicit patch or remediation level is stated in the provided data.

Potential Impact

The vulnerability allows attackers to bypass hostname-based privilege checks by exploiting the incorrect acceptance of certain Punycode-encoded labels. This can result in privilege escalation, where unauthorized users gain elevated access rights. The impact is high confidentiality and integrity compromise without denial of service. No known exploits in the wild have been reported at this time.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Multiple Red Hat advisories reference this CVE, suggesting that fixes may be available in updated packages of Red Hat Ansible Automation Platform and related components. Users should monitor the linked Red Hat advisories for updates and apply security patches once released. Until patches are applied, avoid relying solely on ToASCII and ToUnicode functions from golang.org/x/net/idna for critical privilege checks involving hostnames.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
Go
Date Reserved
2026-04-07T18:13:03.526Z
Cvss Version
null
State
PUBLISHED
Remediation Level
null
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-39821","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30855","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30853","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30854","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30651","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26547","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26546","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:23262","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:23264","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33155","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33160","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33163","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33173","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33183","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30650","vendor":"Red Hat"}]

Threat ID: 6a1079f0e1370fbb48159db0

Added to database: 05/22/2026, 15:44:48 UTC

Last enriched: 07/30/2026, 21:39:05 UTC

Last updated: 07/31/2026, 19:52:01 UTC

Views: 416

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses