Security update for azure-storage-azcopy
This update for azure-storage-azcopy fixes the following issues: Update to 10.32.6. Security issues fixed: - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266657). - CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of truncated/invalid UTF-8 input can lead to infinite loop (bsc#1272123). Other updates and bugfixes: - Version 10.32.6: * Run go mod tidy * Merge tag 'v10.32.4' into release/fips * Merge remote-tracking branch 'origin/wendi/10.32.5' into release/fips * Merge branch 'main' into wendi/10.32.5 * TASK 38260338: Updated the release pipeline to produce Linux builds capable of complying with the FIPS 140-3 standard. (#3488) * Bump Go toolchain and security-relevant dependencies (#3486) * stylistic changes from copilot :) - Update golang.org/x/text to v0.40.0 - Update golang.org/x/net to v0.57.0 - Version 10.32.5: * Create new patch release * Merge branch 'main' into seanmcc/bump-deps-2026-06 * Ensure get/set ACLs are on URLs with paths (#3453) * Print out help command on just `azcopy` (#3485) * Bump Go toolchain and security-relevant dependencies * Centralize HTTP client into a shared global instance (#3436) * Remove 0-padding in mode with SetUID (#3467) * Updated trivy dependency to known safe version (#3421)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for azure-storage-azcopy fixes the following issues: Update to 10.32.6. Security issues fixed: - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266657). - CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of truncated/invalid UTF-8 input can lead to infinite loop (bsc#1272123). Other updates and bugfixes: - Version 10.32.6: * Run go mod tidy * Merge tag 'v10.32.4' into release/fips * Merge remote-tracking branch 'origin/wendi/10.32.5' into release/fips * Merge branch 'main' into wendi/10.32.5 * TASK 38260338: Updated the release pipeline to produce Linux builds capable of complying with the FIPS 140-3 standard. (#3488) * Bump Go toolchain and security-relevant dependencies (#3486) * stylistic changes from copilot :) - Update golang.org/x/text to v0.40.0 - Update golang.org/x/net to v0.57.0 - Version 10.32.5: * Create new patch release * Merge branch 'main' into seanmcc/bump-deps-2026-06 * Ensure get/set ACLs are on URLs with paths (#3453) * Print out help command on just `azcopy` (#3485) * Bump Go toolchain and security-relevant dependencies * Centralize HTTP client into a shared global instance (#3436) * Remove 0-padding in mode with SetUID (#3467) * Updated trivy dependency to known safe version (#3421)
05 / REFERENCES