[CLSA-2026:1785833533] golang: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-04 08:52:25 UTC
Description:
- CVE-2026-27142: escape URLs in the url= portion of html/template content attributes, closing a cross-site scripting vector - CVE-2026-39823: skip ASCII whitespace around the url= separator so the new content escaper cannot be bypassed
Updated packages:
  • go-toolset-1.22.9-1.el9_2.tuxcare.els22.x86_64.rpm
    sha:2e6f082d6078a6dba15f1b28cc149c8daca241172dc8caef0c0632dbc10baaac
  • golang-1.22.9-1.el9_2.tuxcare.els22.x86_64.rpm
    sha:bc0041eaf002469a4bea975b8ea118e6d77dacf178fbb3271d0727cd5c7fd128
  • golang-bin-1.22.9-1.el9_2.tuxcare.els22.x86_64.rpm
    sha:59eafa9c0724f5c6d57a2bb7c6862c5fcf18aac09f99da7b9d7fc718b0b9eb4b
  • golang-docs-1.22.9-1.el9_2.tuxcare.els22.noarch.rpm
    sha:4117a7d19ed413ac9fe0395a24ae4c951958d9c0333a38482da1c4180a21032b
  • golang-misc-1.22.9-1.el9_2.tuxcare.els22.noarch.rpm
    sha:b200ede4df1c8deffb7243c5588017f82af3ad1462b6bb164da12b81dd33fef9
  • golang-src-1.22.9-1.el9_2.tuxcare.els22.noarch.rpm
    sha:9a18c4d26a3baa0090a09f5f53161ad67d138eb9112b4f7cfcb4171d8f1cad9c
  • golang-tests-1.22.9-1.el9_2.tuxcare.els22.noarch.rpm
    sha:cc3e8d29a597af8550de2d707c1de63d05530eb4ec3280e0950fac0f7382964a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.