- What: Security, bug fix, and enhancement update for golang in Red Hat Enterprise Linux 10
- Impact: Systems using golang are affected
Red Hat Product Errata RHSA-2026:60306 - Security Advisory Issued: 2026-08-26 Updated: 2026-08-26 RHSA-2026:60306 - Security Advisory Overview Updated Packages Synopsis Important: golang security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for golang is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The golang packages provide the Go programming language compiler. Security Fix(es): encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) net/ http: golang: Go net/ http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) Bug Fix(es) and Enhancement(s): Update Go to version 1.26.7+1 [rhel-10.2.z] (JIRA:RHEL-246423) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2515815 - CVE-2026-33818 encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal BZ - 2515820 - CVE-2026-56860 net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution BZ - 2515827 - CVE-2026-56853 net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service BZ - 2515838 - CVE-2026-56858 html/template: golang: Go html/template: Cross-Site Scripting via pathological input BZ - 2515839 - CVE-2026-56862 crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages BZ - 2515840 - CVE-2026-56859 encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue RHEL-246423 - Update Go to version 1.26.7+1 [rhel-10.2.z] CVEs CVE-2026-33818 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM golang-1.26.7-1.el10_2.src.rpm SHA-256: 4d0ee0fde7f466fa6cf7b60d624ba4dbd5ca3f49584d2696565eace5c8382c5d x86_64 go-toolset-1.26.7-1.el10_2.x86_64.rpm SHA-256: 3d5709c1519012f7cca60e436e154828fc9ddb97e9a9621f1dae987935247612 golang-1.26.7-1.el10_2.x86_64.rpm SHA-256: ee945bd180f1683b9e29a77fa1cd12842c759f95796385e3248bb73a5f27cd79 golang-bin-1.26.7-1.el10_2.x86_64.rpm SHA-256: 90e7cacb08933e095b2013aae11c50f7ab4fda8cbe71f050b897fb41336e018c golang-docs-1.26.7-1.el10_2.noarch.rpm SHA-256: e33831a0f07744ee363326d7fbf0d1b8f9f6f58ad501d0a287bf83463092186e golang-misc-1.26.7-1.el10_2.noarch.rpm SHA-256: 060b8e55088891fbd0450fb526f9d539fec03e63de1d1d45ac1d5c08d39974ac golang-race-1.26.7-1.el10_2.x86_64.rpm SHA-256: f976e6027f2f661782de1a0176aafdf9523ef396573c9f7e5176d62e045e5822 golang-src-1.26.7-1.el10_2.noarch.rpm SHA-256: c37617677f14a61fc7150c7d751719452f3a0e8959693352a7a405ebdf2172c2 golang-tests-1.26.7-1.el10_2.noarch.rpm SHA-256: f2f6d6b6e39d43aec8260d0313e6646194327feb9655d1164f0f3381a7915879 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM golang-1.26.7-1.el10_2.src.rpm SHA-256: 4d0ee0fde7f466fa6cf7b60d624ba4dbd5ca3f49584d2696565eace5c8382c5d x86_64 go-toolset-1.26.7-1.el10_2.x86_64.rpm SHA-256: 3d5709c1519012f7cca60e436e154828fc9ddb97e9a9621f1dae987935247612 golang-1.26.7-1.el10_2.x86_64.rpm SHA-256: ee945bd180f1683b9e29a77fa1cd12842c759f95796385e3248bb73a5f27cd79 golang-bin-1.26.7-1.el10_2.x86_64.rpm SHA-256: 90e7cacb08933e095b2013aae11c50f7ab4fda8cbe71f050b897fb41336e018c golang-docs-1.26.7-1.el10_2.noarch.rpm SHA-256: e33831a0f07744ee363326d7fbf0d1b8f9f6f58ad501d0a287bf83463092186e golang-misc-1.26.7-1.el10_2.noarch.rpm SHA-256: 060b8e55088891fbd0450fb526f9d539fec03e63de1d1d45ac1d5c08d39974ac golang-race-1.26.7-1.el10_2.x86_64.rpm SHA-256: f976e6027f2f661782de1a0176aafdf9523ef396573c9f7e5176d62e045e5822 golang-src-1.26.7-1.el10_2.noarch.rpm SHA-256: c37617677f14a61fc7150c7d751719452f3a0e8959693352a7a405ebdf2172c2 golang-tests-1.26.7-1.el10_2.noarch.rpm SHA-256: f2f6d6b6e39d43aec8260d0313e6646194327feb9655d1164f0f3381a7915879 Red Hat Enterprise Linux for IBM z Systems 10 SRPM golang-1.26.7-1.el10_2.src.rpm SHA-256: 4d0ee0fde7f466fa6cf7b60d624ba4dbd5ca3f49584d2696565eace5c8382c5d s390x go-toolset-1.26.7-1.el10_2.s390x.rpm SHA-256: 80afaadb3a184e129d5d554446cf3ff64d19ab5d69dcbe5f6930efcefe04aa06 golang-1.26.7-1.el10_2.s390x.rpm SHA-256: e9a7f9b9cf27cc66d7da6a2e82e692ae7c48134859c610a475c3384c46471374 golang-bin-1.26.7-1.el10_2.s390x.rpm SHA-256: 1813c122fb585bce0de73efef8eee66ae34141dd0e4679425278eff8846003e3 golang-docs-1.26.7-1.el10_2.noarch.rpm SHA-256: e33831a0f07744ee363326d7fbf0d1b8f9f6f58ad501d0a287bf83463092186e golang-misc-1.26.7-1.el10_2.noarch.rpm SHA-256: 060b8e55088891fbd0450fb526f9d539fec03e63de1d1d45ac1d5c08d39974ac golang-race-1.26.7-1.el10_2.s390x.rpm SHA-256: d116ab5ac1d8212f1137a5038ecf274c95fa75f599110ebd5a4f30edd7838074 golang-src-1.26.7-1.el10_2.noarch.rpm SHA-256: c37617677f14a61fc7150c7d751719452f3a0e8959693352a7a405ebdf2172c2 golang-tests-1.26.7-1.el10_2.noarch.rpm SHA-256: f2f6d6b6e39d43aec8260d0313e6646194327feb9655d1164f0f3381a7915879 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM golang-1.26.7-1.el10_2.src.rpm SHA-256: 4d0ee0fde7f466fa6cf7b60d624ba4dbd5ca3f49584d2696565eace5c8382c5d s390x go-toolset-1.26.7-1.el10_2.s390x.rpm SHA-256: 80afaadb3a184e129d5d554446cf3ff64d19ab5d69dcbe5f6930efcefe04aa06 golang-1.26.7-1.el10_2.s390x.rpm SHA-256: e9a7f9b9cf27cc66d7da6a2e82e692ae7c48134859c610a475c3384c46471374 golang-bin-1.26.7-1.el10_2.s390x.rpm SHA-256: 1813c122fb585bce0de73efef8eee66ae34141dd0e4679425278eff8846003e3 golang-docs-1.26.7-1.el10_2.noarch.rpm SHA-256: e33831a0f07744ee363326d7fbf0d1b8f9f6f58ad501d0a287bf83463092186e golang-misc-1.26.7-1.el10_2.noarch.rpm SHA-256: 060b8e55088891fbd0450fb526f9d539fec03e63de1d1d45ac1d5c08d39974ac golang-race-1.26.7-1.el10_2.s390x.rpm SHA-256: d116ab5ac1d8212f1137a5038ecf274c95fa75f599110ebd5a4f30edd7838074 golang-src-1.26.7-1.el10_2.noarch.rpm SHA-256: c37617677f14a61fc7150c7d751719452f3a0e8959693352a7a405ebdf2172c2 golang-tests-1.26.7-1.el10_2.noarch.rpm SHA-256: f2f6d6b6e39d43aec8260d0313e6646194327feb9655d1164f0f3381a7915879 Red Hat Enterprise Linux for Power, little endian 10 SRPM golang-1.26.7-1.el10_2.src.rpm SHA-256: 4d0ee0fde7f466fa6cf7b60d624ba4dbd5ca3f49584d2696565eace5c8382c5d ppc64le go-toolset-1.26.7-1.el10_2.ppc64le.rpm SHA-256: 5451cec28e79636a86b78a87541490185f1e18ecbca440aef89b3bf667eae4cc golang-1.26.7-1.el10_2.ppc64le.rpm SHA-256: 73ee1f58a999198375c1c16e884b89728b0845f5b3120922aa8bc815e1c3552f golang-bin-1.26.7-1.el10_2.ppc64le.rpm SHA-256: 8afac675de6ea52f702643552ff43728dd89b67d7b1db4f0782546a6dead52f4 golang-docs-1.26.7-1.el10_2.noarch.rpm SHA-256: e33831a0f07744ee363326d7fbf0d1b8f9f6f58ad501d0a287bf83463092186e golang-misc-1.26.7-1.el10_2.noarch.rpm SHA-256: 060b8e55088891fbd0450fb526f9d539fec03e63de1d1d45ac1d5c08d39974ac golang-race-1.26.7-1.el10_2.ppc64le.rpm SHA-256: bc335b70416486f9462a6f19674ac54217fea158a01612fc8e6f229252b5ac0a golang-src-1.26.7-1.el10_2.noarch.rpm SHA-256: c37617677f14a61fc7150c7d751719452f3a0e8959693352a7a405ebdf2172c2 golang-tests-1.26.7-1.el10_2.noarch.rpm SHA-256: f2f6d6b6e39d43aec8260d0313e6646194327feb9655d1164f0f3381a7915879 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM golang-1.26.7-1.el10_2.src.rpm SHA-256: 4d0ee0fde7f466fa6cf7b60d624ba4dbd5ca3f49584d2696565eace5c8382c5d ppc64le go-toolset-1.26.7-1.el10_2.ppc64le.rpm SHA-256: 5451cec28e79636a86b78a87541490185f1e18ecbca440aef89b3bf667eae4cc golang-1.26.7-1.el10_2.ppc64le.rpm SHA-256: 73ee1f58a999198375c1c16e884b89728b0845f5b3120922aa8bc815e1c3552f golang-bin-1.26.7-1.el10_2.ppc64le.rpm SHA-256: 8afac675de6ea52f702643552ff43728dd89b67d7b1db4f0782546a6dead5