[Git][security-tracker-team/security-tracker][master] Track fixed version for golang-1.27 issues fixed via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 17 06:25:52 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1814a5fa by Salvatore Bonaccorso at 2026-08-17T07:25:03+02:00
Track fixed version for golang-1.27 issues fixed via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5643,7 +5643,7 @@ CVE-2026-73252 [Built-in TLS short-record handling]
 CVE-2026-73251 [Built-in TLS certificate-chain verification with CA bundles]
 	- mongoose 7.23+ds-1
 CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to two sumdb  ...)
-	- golang-1.27 <unfixed> (bug #1144340)
+	- golang-1.27 1.27~rc3-1 (bug #1144340)
 	- golang-1.26 1.26.6-1 (bug #1144341)
 	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
@@ -5655,7 +5655,7 @@ CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to two
 	NOTE: Fixed by: https://github.com/golang/go/commit/115eb476aaca4531374c42e19e6f199265c2e25e (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/b0b8c97d1386bb3eb978e727ed0b1df8e14df569 (go1.25.13)
 CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module content no ...)
-	- golang-1.27 <unfixed> (bug #1144340)
+	- golang-1.27 1.27~rc3-1 (bug #1144340)
 	- golang-1.26 1.26.6-1 (bug #1144341)
 	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
@@ -5667,7 +5667,7 @@ CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module cont
 	NOTE: Fixed by: https://github.com/golang/go/commit/9f6980fd5c03840b0f6764e8ec7c705b90989eee (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/22e01669cdcabb9cfad02e0c2bffbce8198f6bfb (go1.25.13)
 CVE-2026-56859 (Previously, DecodeElement would reset the depth counter causing it to  ...)
-	- golang-1.27 <unfixed> (bug #1144340)
+	- golang-1.27 1.27~rc3-1 (bug #1144340)
 	- golang-1.26 1.26.6-1 (bug #1144341)
 	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
@@ -5679,7 +5679,7 @@ CVE-2026-56859 (Previously, DecodeElement would reset the depth counter causing
 	NOTE: Fixed by: https://github.com/golang/go/commit/9918f26ab31a6bf9209ecc06465cab0e287e90f1 (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/b952d04e2ab03d7b9049b2909e66dc91707089b4 (go1.25.13)
 CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it reads a  ...)
-	- golang-1.27 <unfixed> (bug #1144340)
+	- golang-1.27 1.27~rc3-1 (bug #1144340)
 	- golang-1.26 1.26.6-1 (bug #1144341)
 	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
@@ -5691,7 +5691,7 @@ CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it re
 	NOTE: Fixed by: https://github.com/golang/go/commit/5bbd22ff78daf010c5bd19c466a0c45ac78503d4 (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/784132491b1002342026712477725c0d742a53e8 (go1.25.13)
 CVE-2026-56860 (Previously, resolving relative paths containing parent directory ('..' ...)
-	- golang-1.27 <unfixed> (bug #1144340)
+	- golang-1.27 1.27~rc3-1 (bug #1144340)
 	- golang-1.26 1.26.6-1 (bug #1144341)
 	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
@@ -5703,7 +5703,7 @@ CVE-2026-56860 (Previously, resolving relative paths containing parent directory
 	NOTE: Fixed by: https://github.com/golang/go/commit/128893dbf9a6b4d6e7c99942096e2c0018d6fe57 (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/962b300d32b68fd5f3c11674f711fc0e86251664 (go1.25.13)
 CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered as state- ...)
-	- golang-1.27 <unfixed> (bug #1144340)
+	- golang-1.27 1.27~rc3-1 (bug #1144340)
 	- golang-1.26 1.26.6-1 (bug #1144341)
 	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
@@ -5715,7 +5715,7 @@ CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered as
 	NOTE: Fixed by: https://github.com/golang/go/commit/b6432317a176b1b5595aa597dc1864a4cc4a81b2 (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/677cfe54ecac147c4992e38204641bf61662524f (go1.25.13)
 CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' early, al ...)
-	- golang-1.27 <unfixed> (bug #1144340)
+	- golang-1.27 1.27~rc3-1 (bug #1144340)
 	- golang-1.26 1.26.6-1 (bug #1144341)
 	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
@@ -5727,7 +5727,7 @@ CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' ear
 	NOTE: Fixed by: https://github.com/golang/go/commit/33ecb966ca47e55034272a9146e23e9909507f6d (go1.26.6)
 	NOTE: Fixed by: https://github.com/golang/go/commit/cafd3448c7cb0b2d793bb4144d58f72ef3f48327 (go1.25.13)
 CVE-2026-33818 (Enforce a recursion limit in Unmarshal to prevent stack exhaustion whe ...)
-	- golang-1.27 <unfixed> (bug #1144340)
+	- golang-1.27 1.27~rc3-1 (bug #1144340)
 	- golang-1.26 1.26.6-1 (bug #1144341)
 	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1814a5fadd4d848d03ffd8b77f760d6bd2483b75

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1814a5fadd4d848d03ffd8b77f760d6bd2483b75
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/ffd2652a/attachment.htm>


More information about the debian-security-tracker-commits mailing list