Red Hat Security Advisory: RHACS 4.10.4 security and bug fix update
See the release notes (link in the references section) for a description of the fixes and enhancements in this particular release.
AI Analysis
Technical Summary
CVE-2026-39821 is a vulnerability in golang.org/x/net/idna where the ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to ASCII-only hostnames, such as xn--example-.com being normalized to example.com instead of producing an error. This improper validation can allow an attacker to supply a Punycode hostname that passes an ASCII-only authorization check but is normalized to a restricted ASCII hostname, resulting in privilege escalation. Red Hat products including RHEL, OpenShift, and Advanced Cluster Security that ship the Go toolchain or bundle golang.org/x/net are exposed. The issue is addressed by upgrading to a fixed golang.org/x/net release with the corrected idna handling.
Potential Impact
The vulnerability allows privilege escalation by bypassing hostname validation checks, potentially granting unauthorized access to restricted hostnames. The impact is rated high by Red Hat, with confidentiality and integrity impacts considered high, but no availability impact. The exposure is broad across multiple Red Hat products that include the affected Go packages.
Mitigation Recommendations
Red Hat advises upgrading to the fixed golang.org/x/net release that includes the corrected idna processing. This is done via updated golang or dependent package rebuilds provided by Red Hat. Users should apply the security updates released by Red Hat for their affected products as detailed in the Red Hat Security Advisory RHSA-2026:26546. No alternative mitigations are specified.
Red Hat Security Advisory: RHACS 4.10.4 security and bug fix update
Description
See the release notes (link in the references section) for a description of the fixes and enhancements in this particular release.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-39821 is a vulnerability in golang.org/x/net/idna where the ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to ASCII-only hostnames, such as xn--example-.com being normalized to example.com instead of producing an error. This improper validation can allow an attacker to supply a Punycode hostname that passes an ASCII-only authorization check but is normalized to a restricted ASCII hostname, resulting in privilege escalation. Red Hat products including RHEL, OpenShift, and Advanced Cluster Security that ship the Go toolchain or bundle golang.org/x/net are exposed. The issue is addressed by upgrading to a fixed golang.org/x/net release with the corrected idna handling.
Potential Impact
The vulnerability allows privilege escalation by bypassing hostname validation checks, potentially granting unauthorized access to restricted hostnames. The impact is rated high by Red Hat, with confidentiality and integrity impacts considered high, but no availability impact. The exposure is broad across multiple Red Hat products that include the affected Go packages.
Mitigation Recommendations
Red Hat advises upgrading to the fixed golang.org/x/net release that includes the corrected idna processing. This is done via updated golang or dependent package rebuilds provided by Red Hat. Users should apply the security updates released by Red Hat for their affected products as detailed in the Red Hat Security Advisory RHSA-2026:26546. No alternative mitigations are specified.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:26546
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-46595"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a32cf199f87a2db092a4a05
Added to database: 06/17/2026, 16:45:13 UTC
Last enriched: 08/14/2026, 23:43:43 UTC
Last updated: 09/14/2026, 00:52:57 UTC
Views: 112
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.