« Volver al listado

CVE-2026-42507

Estado: Pendiente de análisisMedia (5.3)—

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-42507",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-42507",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-03T19:04:08.223332Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@golang.org",
      "affectedData": [
        {
          "vendor": "Go standard library",
          "product": "net/textproto",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.25.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.26.0-0",
              "lessThan": "1.26.4",
              "versionType": "semver"
            }
          ],
          "packageName": "net/textproto",
          "collectionURL": "https://pkg.go.dev",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "parseCodeLine"
            },
            {
              "name": "Reader.ReadCodeLine"
            },
            {
              "name": "readMIMEHeader"
            },
            {
              "name": "Error.Error"
            },
            {
              "name": "Reader.ReadMIMEHeader"
            },
            {
              "name": "Reader.ReadResponse"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-02T23:16:38.027",
  "references": [
    {
      "url": "https://go.dev/cl/777060",
      "source": "security@golang.org"
    },
    {
      "url": "https://go.dev/issue/79346",
      "source": "security@golang.org"
    },
    {
      "url": "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw",
      "source": "security@golang.org"
    },
    {
      "url": "https://pkg.go.dev/vuln/GO-2026-5039",
      "source": "security@golang.org"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."
    },
    {
      "lang": "es",
      "value": "Al devolver errores, las funciones en el paquete net/textproto incluirían su entrada como parte del error. Esto podría permitir a un atacante inyectar contenido engañoso en errores que son impresos o registrados."
    }
  ],
  "lastModified": "2026-07-22T19:10:00.120",
  "sourceIdentifier": "security@golang.org"
}