Junglewise Threat Intelligence

CVE-2026-42507: Google Go log injection in net/textproto package

CVE-2026-42507 · Severity: info · Published 2026-06-02

Technologies: stdlib (Go). Vendors: Go, Google.

Executive brief

A vulnerability in the Go programming language's standard library could allow attackers to manipulate application logs or error messages. By sending specially crafted input to services using the affected library, an attacker can inject misleading text or fake error entries into system logs. This can be used to hide malicious activity or deceive administrators during incident investigations.

Technical details

A log injection vulnerability exists in the Go net/textproto package due to the inclusion of unescaped arbitrary input in returned error strings. Functions such as Reader.ReadCodeLine, Reader.ReadMIMEHeader, and Reader.ReadResponse are affected. An attacker can provide input containing newline characters or other control sequences to inject misleading content into logs or error displays in downstream packages like net/http and net/smtp. This is primarily a public-track issue with limited impact on integrity and availability, but it can be used to obfuscate attacks. The issue is fixed in Go versions 1.25.11 and 1.26.4.

Affected products

  • Google Go before 1.25.11, 1.26.0 before 1.26.4

Timeline

  • 2026-05-11: disclosed: Issue opened on GitHub
  • 2026-06-02: advisory: NVD and Go project published advisory

References

Related threats