CVE-2026-25679

Publication date 9 March 2026

Last updated 9 March 2026


Ubuntu priority

Description

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

Status

Package Ubuntu Release Status
golang-1.24 25.10 questing
Needs evaluation
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
golang-1.25 25.10 questing
Needs evaluation
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
golang-1.26 25.10 questing Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release