Linuxsecurity SUSE Releases Security Updates for Go1.25 and Go1.26 Addressing Multiple CVEs
Article Content
- •SUSE issued updates for Go1.25 and Go1.26 to address three CVEs.
- •CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 were published on June 2, 2026.
- •The updates are rated as moderate, and users are urged to apply them to prevent exploitation.
SUSE has released security updates for Go versions 1.25 and 1.26, addressing three critical vulnerabilities identified as CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507. These vulnerabilities affect the crypto/x509, mime, and net/textproto packages, posing risks such as arbitrary input handling and quadratic complexity issues. The vulnerabilities were published on June 2, 2026, with the first public proof of concept for CVE-2026-27145 appearing on June 3, 2026. The updates are rated as moderate, and users are advised to apply the patches promptly to mitigate potential exploitation. The vulnerabilities could allow attackers to manipulate data processing and potentially execute arbitrary code. Both updates were released on June 9, 2026, and are crucial for maintaining the security of applications utilizing these Go versions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track SuSE and CVE-2026-27145 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Denial of Service Vulnerability in grpcurl Affects Fedora Systems A denial of service vulnerability (CVE-2026-27145) has been identified in grpcurl, a command-line tool for interacting with gRPC servers, affecting Fedora systems. The vulnerability allows for excessive processing of DNS SAN entries, potentially leading to service disruption. Fedora versions 1.9.3 and earlier are…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…