Vulnerability GO-2026-5026

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
4 months ago
May 22, 2026 at 02:46 AM UTC
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
v0.1.0 - v0.54.0
v0.1.0 - v0.54.0

Summary

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

Details

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error.

This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

Timeline

Published
4 months ago
May 22, 2026 at 02:46 AM UTC
Last Modified
3 days ago
October 02, 2026 at 10:41 AM UTC