Golang: stdlib: security update to 1.26.9stdlib: security update to 1.27.2

high Tenable Self-Hosted Container Security Plugin ID 473921

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body
directly to the connection without framing after the request headers. If the server rejects the CONNECT
request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because
CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a
subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and
causing the next caller that reuses it to read the response to the injected request. In reverse proxies
(including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead
to cross-user response poisoning. (CVE-2026-56866)

Solution

Update the stdlib library and its related packages to version 1.26.9 or later.

See Also

https://pkg.go.dev/vuln/GO-2026-6605

Plugin Details

Severity: High

ID: 473921

Version: Revision 1.1

Type: Local

Family: Golang

Published: 10/9/2026

Updated: 10/9/2026

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2026-56866

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/8/2026

Vulnerability Publication Date: 10/8/2026

Reference Information

CVE: CVE-2026-56866