Red Hat Security Advisory: go-fdo-server security update
This package provides a server-side implementation of the FIDO Device Onboard (FDO) specification, written in Go. FDO is an open standard for the late binding of device credentials, allowing for automated and secure on-boarding of devices when they are first powered on in their final location. Security Fix(es): * github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability (CVE-2026-33816) * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
This security advisory addresses two vulnerabilities in the go-fdo-server package used in Red Hat Enterprise Linux 10. The first is a memory-safety vulnerability in the github.com/jackc/pgx/v5 library (CVE-2026-33816). The second is a denial of service vulnerability in the Go crypto/tls package caused by multiple TLS 1.3 key update messages (CVE-2026-32283). The advisory provides updated packages to remediate these issues. The vulnerabilities have been rated with a high severity impact, particularly due to the denial of service potential. The advisory references Red Hat's errata RHSA-2026:19137 for detailed patch and update instructions.
Potential Impact
The denial of service vulnerability (CVE-2026-32283) in the Go crypto/tls package can cause service disruption by exploiting multiple TLS 1.3 key update messages. The memory-safety vulnerability (CVE-2026-33816) in the pgx library could lead to undefined behavior or crashes. Both vulnerabilities impact the availability and stability of the go-fdo-server service. There is no indication of confidentiality or integrity impact. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released updated go-fdo-server packages for Red Hat Enterprise Linux 10 that address these vulnerabilities. Users should apply the security update as described in Red Hat advisory RHSA-2026:19137 and the related article https://access.redhat.com/articles/11258. Applying these updates will remediate the denial of service and memory-safety issues. No additional mitigation actions are specified or required beyond applying the official patches.
Red Hat Security Advisory: go-fdo-server security update
Description
This package provides a server-side implementation of the FIDO Device Onboard (FDO) specification, written in Go. FDO is an open standard for the late binding of device credentials, allowing for automated and secure on-boarding of devices when they are first powered on in their final location. Security Fix(es): * github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability (CVE-2026-33816) * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVSS v3.1
Score 7.5high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This security advisory addresses two vulnerabilities in the go-fdo-server package used in Red Hat Enterprise Linux 10. The first is a memory-safety vulnerability in the github.com/jackc/pgx/v5 library (CVE-2026-33816). The second is a denial of service vulnerability in the Go crypto/tls package caused by multiple TLS 1.3 key update messages (CVE-2026-32283). The advisory provides updated packages to remediate these issues. The vulnerabilities have been rated with a high severity impact, particularly due to the denial of service potential. The advisory references Red Hat's errata RHSA-2026:19137 for detailed patch and update instructions.
Potential Impact
The denial of service vulnerability (CVE-2026-32283) in the Go crypto/tls package can cause service disruption by exploiting multiple TLS 1.3 key update messages. The memory-safety vulnerability (CVE-2026-33816) in the pgx library could lead to undefined behavior or crashes. Both vulnerabilities impact the availability and stability of the go-fdo-server service. There is no indication of confidentiality or integrity impact. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released updated go-fdo-server packages for Red Hat Enterprise Linux 10 that address these vulnerabilities. Users should apply the security update as described in Red Hat advisory RHSA-2026:19137 and the related article https://access.redhat.com/articles/11258. Applying these updates will remediate the denial of service and memory-safety issues. No additional mitigation actions are specified or required beyond applying the official patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:19137
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-33816"]
- Cvss Version
- 3.1
Threat ID: 6a160978e29bf47b50644e67
Added to database: 05/26/2026, 20:58:32 UTC
Last enriched: 07/30/2026, 11:00:57 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 60
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.