CVE-2026-39836
High
Panic in Dial and LookupPort when handling NUL byte on Windows in net
The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
Exploit probability
0.6%
Published
May 11, 2026
Required by
Not available
Last source change
May 11, 2026
02 / AFFECTED SOFTWARE
Affected packages
152 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2026-39836
View original source
The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
Open Source Vulnerabilities
BIT-golang-2026-39836
View original source
The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
Open Source Vulnerabilities
GO-2026-4971
View original source
The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
05 / REFERENCES