CVE-2026-39836
published 2026-05-07CVE-2026-39836: The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.59%
46.0th percentile
The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| go_standard_library | net | < 1.25.10 | 1.25.10 |
| go_standard_library | net | >= 1.26.0-0 < 1.26.3 | 1.26.3 |
| golang | go | < 1.25.10 | 1.25.10 |
| golang | go | >= 1.26.0 < 1.26.3 | 1.26.3 |
| multicluster-engine | maestro-rhel9 | — | — |
| oadp | oadp-velero-rhel9 | — | — |
| openshift4 | ose-hypershift-rhel9 | — | — |
| rhtas | ec-rhel9 | — | — |
| web-terminal | web-terminal-exec-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8g2r-hhvj-mv99: The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)
ghsa_unreviewed·2026-05-07
CVE-2026-39836 [HIGH] GHSA-8g2r-hhvj-mv99: The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)
The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
VulDB
net up to 1.25.9/1.26.2 on Go Dial/LookupPort uncaught exception (EUVD-2026-28427)
vuldb·2026-05-07
CVE-2026-39836 [LOW] net up to 1.25.9/1.26.2 on Go Dial/LookupPort uncaught exception (EUVD-2026-28427)
A vulnerability described as problematic has been identified in net up to 1.25.9/1.26.2 on Go. Affected is the function Dial/LookupPort. Executing a manipulation can lead to uncaught exception.
The identification of this vulnerability is CVE-2026-39836. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
Red Hat
net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows
vendor_redhat·2026-05-07·CVSS 7.5
CVE-2026-39836 [HIGH] CWE-617 net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows
net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows
The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
A flaw was found in the `net` package of Go (golang). When running on Windows, the `Dial` and `LookupPort` functions can panic if they receive an input containing a NUL (0) byte. This can be triggered by a remote attacker providing a specially crafted input, leading to a denial of service (DoS) for applications using these functions.
Statement: This denial of service flaw exists within the Go `net` package, specifically impacting applications when executed on Microsoft Windows operating systems. Red Hat Product Security has rated this flaw as a Moderate as Red Hat products primarily deploy Go ap
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-39836 net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows
bugzilla·2026-05-07·CVSS 7.5
CVE-2026-39836 [HIGH] CVE-2026-39836 net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows
CVE-2026-39836 net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows
The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:22120 https://access.redhat.com/errata/RHSA-2026:22120
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:22121 https://access.redhat.com/errata/RHSA-2026:22121
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2026:22112 https://access.redhat.com/errata/RHSA-2026:22112
Rapid7
Patch Tuesday - May 2026
blogs_rapid7·2026-05-13·CVSS 10.0
CVE-2026-41089 [CRITICAL] Patch Tuesday - May 2026
Microsoft is publishing 137 vulnerabilities on May 2026 Patch Tuesday . Microsoft is not aware of exploitation in the wild or public disclosure for any of these vulnerabilities. So far this month, Microsoft has provided patches to address 133 browser vulnerabilities, which are not included in the Patch Tuesday count above.
## Windows Netlogon: critical RCE
Anyone responsible for securing a domain controller should prioritize remediation of CVE-2026-41089 , which is a critical stack-based buffer overflow in Windows Netlogon with a CVSS v3 base score of 9.8. Exploitation leads to execution in the context of the Netlogon service, so that’s SYSTEM privileges on the domain controller. For most pentesters, that’s the point at which the customer report more or less writes itself. No privileges
2026-05-07
Published