GO-2026-5006 points to incorrect CVE/changelist

73 views
Skip to first unread message

Atharva Shinde

unread,
Aug 10, 2026, 1:29:45 PM (2 days ago) Aug 10
to golang-dev

The GO-2026-5006 vulnerability report, an alias of CVE-2026-39832, refers to the changelist https://go-review.googlesource.com/c/crypto/+/778642, however this changelist contains the fix for CVE-2026-39833. Looks like the GO-2026-5005 and GO-2026-5006 CVE/changelist references were interchanged.

Moreover, the records of CVE-2026-39832 and CVE-2026-39833 on cve.org also contain this inconsistency. 

I have raised an issue(https://github.com/golang/vulndb/issues/6150) on the golang/vulndb repository. Please take a look.

Thank you for all your work!
Atharva Shinde
Reply all
Reply to author
Forward
0 new messages