The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json
https://pkg.go.dev/vuln/GO-2026-5026
https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
https://bugzilla.redhat.com/show_bug.cgi?id=2480756
https://access.redhat.com/security/cve/CVE-2026-39821
https://access.redhat.com/errata/RHSA-2026:34364
https://access.redhat.com/errata/RHSA-2026:34359
https://access.redhat.com/errata/RHSA-2026:34357
https://access.redhat.com/errata/RHSA-2026:34342
https://access.redhat.com/errata/RHSA-2026:33531
https://access.redhat.com/errata/RHSA-2026:33524
https://access.redhat.com/errata/RHSA-2026:33183
https://access.redhat.com/errata/RHSA-2026:33173
https://access.redhat.com/errata/RHSA-2026:33163
https://access.redhat.com/errata/RHSA-2026:33160
https://access.redhat.com/errata/RHSA-2026:33155
https://access.redhat.com/errata/RHSA-2026:30855
https://access.redhat.com/errata/RHSA-2026:30854
https://access.redhat.com/errata/RHSA-2026:30853
https://access.redhat.com/errata/RHSA-2026:30651
https://access.redhat.com/errata/RHSA-2026:30650
https://access.redhat.com/errata/RHSA-2026:26547
https://access.redhat.com/errata/RHSA-2026:26546