Launch Week Day 1: Announcing Security Design Review
UNKNOWN Go

Arbitrary inputs are included in errors without any escaping in net/textproto

GO-2026-5039 · BIT-golang-2026-42507 · CVE-2026-42507

Published · Modified

Description

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

Ready to move

Start Securing

Free, no credit card | First findings in minutes