Radar: advisory USN-8900-1, published on the Ubuntu Security feed on 7 October 2026 (19:09 UTC). The received text is an automatic translation and covers the Go Networking package. The flaws involve HTTP/2, HTML parsing and IDNA. In HTTP/2, improper handling of server errors after a GOAWAY frame during connection shutdown can hang the connection (CVE-2022-27664), and HPACK header decoding has quadratic complexity (CVE-2022-41723). In HTML parsing, text nodes outside the HTML namespace are rendered as literal text without escaping, which may allow XSS (CVE-2023-3978). Other HTML inputs cause non-linear parsing relative to length (CVE-2024-45338), tags in foreign content with unquoted attribute values ending in a slash are treated as self-contained and place content in the wrong scope, which may allow XSS (CVE-2025-22872), there is quadratic parsing complexity (CVE-2025-47911) and an infinite loop (CVE-2025-58190). In IDNA, Punycode labels that decode only to ASCII are wrongly accepted, which may allow bypassing access controls and escalating privileges (CVE-2026-39821). To verify, consult the original advisory on the Ubuntu Security site using the number USN-8900-1, check the installed package version and compare it with the fixed version listed there.
Cyber ·
USN-8900-1: flaws in the Go Networking package across HTTP/2, HTML and IDNA
Ubuntu Security advisory dated 7 October 2026 lists eight CVEs in the Go Networking package, with possible denial of service, XSS and access control bypass.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.