Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
open-source-dependency-vulnerabilitywidely-deployed-product-advisoryendpoint-software-vulnerabilitybuild-pipeline-compromise

Security Patches and Vulnerability Disclosures in Deno, glibc, and Go

Updated 2mo agoFirst seen Jan 19, 202615 sources

Multiple upstream language/runtime and core library projects disclosed and/or patched significant vulnerabilities affecting widely deployed developer and production environments. Deno reported two issues: CVE-2026-22863 (CVSS 9.2) in the node:crypto compatibility layer where cipher.final() fails to properly finalize/close cipher state, enabling “infinite encryptions” that could aid attacks aimed at learning server secrets; and CVE-2026-22864, a Windows-specific command execution weakness involving a bypass in Deno.Command protections when executing batch files, undermining intended shell-injection safeguards.

glibc maintainers disclosed CVE-2026-0861 (CVSS 8.4), an integer overflow in memalign, posix_memalign, and aligned_alloc affecting versions 2.30–2.42 that can lead to heap corruption when an attacker can control unusually large size values and alignment parameters, and CVE-2026-0915, a decades-old information leak in getnetbyaddr/getnetbyaddr_r affecting versions 2.0–2.42 that can expose uninitialized stack contents to DNS backends when querying a zero-valued network. Separately, the Go team released security updates (Go 1.25.6 and 1.24.12) addressing six vulnerabilities across the standard library (e.g., archive/zip, net/http, crypto/tls) and the toolchain, including a ZIP-processing CPU-exhaustion DoS (CVE-2025-61728) and toolchain issues that could enable command execution in certain developer/build scenarios; organizations running Go services or CI/build pipelines were advised to upgrade to the patched releases.

Share:
Security Patches and Vulnerability Disclosures in Deno, glibc, and Go
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
May 8, 20262mo ago

Go releases 1.26.3 and 1.25.10 with 11 security fixes

The Go team released Go 1.26.3 and Go 1.25.10 to fix 11 vulnerabilities across cmd/go, net/http, net, net/mail, and html/template. The most serious issue, CVE-2026-42501, allowed a malicious module proxy or checksum database to bypass checksum validation, potentially leading to altered modules or Go toolchains being downloaded and executed; other fixes addressed denial-of-service, path and symlink handling, HTTP/2 looping, Windows panics, DNS resolver crashes, and multiple XSS bypasses.

oss-sec: Go 1.26.3 and Go 1.25.10 are released with 11 security fixes
Apr 8, 20263mo ago

Go releases 1.26.2 and 1.25.9 with 10 security fixes

The Go team released Go 1.26.2 and Go 1.25.9 to address 10 vulnerabilities across standard library and toolchain components including os, html/template, crypto/x509, crypto/tls, archive/tar, cmd/compile, and cmd/go. The fixes cover issues such as symlink traversal, XSS, certificate validation and TLS flaws, denial-of-service, memory corruption, and possible arbitrary code execution during build time via cgo and SWIG.

oss-sec: Go 1.26.2 and Go 1.25.9 are released with 10 security fixes
Jan 19, 20265mo ago

Deno vulnerabilities disclosed affecting crypto and Windows command execution

Two Deno flaws were disclosed: CVE-2026-22863 in the Node.js compatibility crypto layer, which can leave ciphers effectively open and risk secret exposure, and CVE-2026-22864, a Windows-specific Deno.Command bypass that can enable arbitrary code execution. Researchers published proof-of-concept details, and users were advised to upgrade to Deno v2.6.0 or later.

glibc discloses heap corruption and information leak vulnerabilities

glibc maintainers disclosed CVE-2026-0861, an integer overflow in memalign-related functions that can lead to heap corruption, and CVE-2026-0915, a long-standing information leak in getnetbyaddr/getnetbyaddr_r that may expose stack contents to a DNS resolver. Administrators were advised to review distribution-specific exposure and apply patches.

Jan 16, 20265mo ago

Go releases 1.25.6 and 1.24.12 to fix six security flaws

The Go team issued security updates Go 1.25.6 and Go 1.24.12 addressing six vulnerabilities, including denial-of-service, TLS session and handshake weaknesses, and cmd/go toolchain issues that could enable arbitrary code execution in some build environments. The fixes were delivered through Go’s scheduled PRIVATE-track minor release process.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

68 LINKEDOpen in app
Vulnerabilities
32 linked
XSS in Go html/template meta refresh content attribute escapingDenial of Service in Go net/mail ParseAddress, ParseAddressList, and ParseDateDouble-free in Go net LookupCNAME with cgo DNS resolverInfinite loop DoS in Go HTTP/2 transport SETTINGS_MAX_FRAME_SIZE handlingPanic in Go net Dial and LookupPort on Windows with NUL-byte inputGo net/http/httputil ReverseProxy query parameter sanitization bypassGo cmd/go checksum database validation bypass via malicious module proxyDoS in Go net/mail consumePhraseGo html/template escaper bypass leads to XSS in <script> blocksSymlink following in Go cmd/go "go bug" temporary filesArbitrary File Write in Go "go tool pack" ExtractionGo html/template meta content URL escaping bypass XSSGo crypto/x509 excluded DNS constraints wildcard case validation bypassGo cmd/compile no-op interface conversion bypasses overlap checkingGo cmd/compile bounds-check elimination memory corruptionInteger overflow in glibc memalign-family functions leads to heap corruptionUnexpected session resumption in Go crypto/tlsDenial of Service in Go archive/zip filename indexingInformation disclosure in Go crypto/tls TLS 1.3 handshake encryption-level processingArbitrary file write in Go cmd/go via malicious #cgo pkg-config directiveUnexpected code execution and arbitrary file write in Go cmd/go VCS handlingMemory exhaustion in Go net/url query parameter parsingglibc getnetbyaddr/getnetbyaddr_r stack information disclosure via zero-valued network DNS queryImproper cipher finalization in Deno node:crypto allows infinite encryptionsDeno Windows batch/cmd spawn restriction bypass via case-sensitive extension checkSymlink traversal race in Go Root.Chmod on LinuxGo crypto/x509 inefficient certificate policy validation DoSXSS in Go html/template JS template literal escapingGo crypto/x509 certificate chain building denial of serviceGo crypto/tls TLS 1.3 KeyUpdate Denial of ServiceArbitrary Code Execution in Go cmd/go via malicious SWIG file namesUnbounded memory allocation in Go archive/tar old GNU sparse map parsing
Affected products
15 linked
GoRcloneGrafanaAlpine LinuxWindowsAlmalinuxOpensslGentoo LinuxUbuntuGitArch LinuxRuncCorednsOpensslDebian
Organizations
21 linked
GoogleOracleGrafana LabsRcloneArch LinuxResticAlpine LinuxAlmalinuxMattermostChainguardGMO Flatt SecurityFreebsdDEVCORECanonicalAppleGitHubDebianOpenwallGentoo FoundationSaintgits College of EngineeringGopass
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Security Patches and Vulnerability Disclosures in Deno, glibc, and Go | Mallory