Vulnerability GO-2026-6608
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
8 hours ago
October 08, 2026 at 10:31 PM UTC
Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart
<1.26.9
<1.26.9
Summary
Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart
Details
Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
8 hours ago
Reset context tracking on consecutive template expressions in html/template
<1.26.9 GO-2026-6599
<1.26.9 GO-2026-6599
Unknown
8 hours ago
Recognize yield as regexp preceder keyword in html/template
<1.26.9 GO-2026-6600
<1.26.9 GO-2026-6600
Unknown
8 hours ago
HTTP/2 server memory exhaustion due to Trailer headers in net/http
<1.26.9, >=1.27.0-0 <1.27.2 GO-2026-6603
<1.26.9, >=1.27.0-0 <1.27.2 GO-2026-6603
Unknown
8 hours ago
Root.Mkdir(All) can follow junctions out of the root on Windows in os
<1.26.9 GO-2026-6604
<1.26.9 GO-2026-6604
Unknown
8 hours ago
HTTP/1 client connection desynchronization after CONNECT rejection in net/http
<1.26.9 GO-2026-6605
<1.26.9 GO-2026-6605
Impacted packages
Timeline
Published
8 hours ago
October 08, 2026 at 10:31 PM UTC
Last Modified
8 hours ago
October 08, 2026 at 11:00 PM UTC