PatchDay Alert

CVE

CVE-2026-39836

0field notes · 1digest CVSS 7.5


Daily digests

Go's `net` package panics when it encounters a NUL byte in Dial or LookupPort calls on Windows. An attacker who can feed crafted input to a Go application's network dialing code can crash the process. This primarily affects Go applications running on Windows, but the Azure Linux packages include Go toolchain and Go-built dependencies like TensorFlow/TensorBoard.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.