Home / mailings [USN-8900-1] Go Networking vulnerabilities
Posted on 07 October 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8900-1
October 07, 2026
golang-golang-x-net vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in Go Networking.
Software Description:
- golang-golang-x-net: Supplementary Go networking libraries
Details:
It was discovered that Go Networking did not properly handle server
errors after sending a GOAWAY frame during HTTP/2 connection shutdown,
which could cause the connection to hang. A remote attacker could
possibly use this issue to cause a denial of service. (CVE-2022-27664)
It was discovered that Go Networking had quadratic complexity when
decoding HPACK headers in HTTP/2 streams. A remote attacker could
possibly use this issue to cause Go Networking to use excessive
resources, leading to a denial of service. (CVE-2022-41723)
It was discovered that Go Networking incorrectly rendered text nodes
outside of the HTML namespace literally, causing text that should be
escaped to not be escaped. A remote attacker could possibly use this
issue to perform cross-site scripting attacks. (CVE-2023-3978)
Guido Vranken discovered that Go Networking processed certain inputs to
the HTML parsing functions non-linearly with respect to their length. A
remote attacker could possibly use this issue to cause Go Networking to
use excessive resources, leading to a denial of service.
(CVE-2024-45338)
Sean Ng discovered that Go Networking incorrectly interpreted tags in
foreign content with unquoted attribute values ending with a solidus
character as self-closing, which could result in content being placed
in the wrong scope during DOM construction. A remote attacker could
possibly use this issue to perform cross-site scripting attacks.
(CVE-2025-22872)
It was discovered that Go Networking had quadratic parsing complexity
when processing certain HTML inputs. A remote attacker could possibly
use this issue to cause Go Networking to use excessive resources,
leading to a denial of service. (CVE-2025-47911)
It was discovered that Go Networking could enter an infinite loop when
parsing certain HTML inputs. A remote attacker could possibly use this
issue to cause Go Networking to use excessive resources, leading to a
denial of service. (CVE-2025-58190)
It was discovered that Go Networking incorrectly accepted
Punycode-encoded labels that decoded to ASCII-only labels when
processing internationalized domain names. A remote attacker could
possibly use this issue to bypass access control restrictions and
escalate privileges. (CVE-2026-39821)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
golang-golang-x-net-dev 1:0.0+git20211209.491a49a+dfsg-1ubuntu0.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8900-1
CVE-2022-27664, CVE-2022-41723, CVE-2023-3978, CVE-2024-45338,
CVE-2025-22872, CVE-2025-47911, CVE-2025-58190, CVE-2026-39821
Package Information:
https://launchpad.net/ubuntu/+source/golang-golang-x-net/1:0.0+git20211209.491a49a+dfsg-1ubuntu0.1
--===============5304448876767467937==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
