Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3376 articles · 142291 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-39836EXPLOITEDPATCHED
microsoft · windows

Panic in Dial and LookupPort when handling NUL byte on Windows in net

Description

The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).

Affected Products

VendorProductVersions
microsoftwindows0, 1.26.0-0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
golanggocert_advisory90%

References

  • https://go.dev/issue/79006
  • https://groups.google.com/g/golang-announce/c/qcCIEXso47M
  • https://go.dev/cl/775320
  • https://pkg.go.dev/vuln/GO-2026-4971

Related News (3 articles)

Tier A
Microsoft MSRC1d ago
CVE-2026-39836 Panic in Dial and LookupPort when handling NUL byte on Windows in net
→ No new info (linked only)
Tier B
BSI Advisories3d ago
[NEU] [mittel] Golang Go: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB4d ago
CVE-2026-39836 | net up to 1.25.9/1.26.2 on Go Dial/LookupPort uncaught exception
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
1.25.101.26.3
PublishedMay 7, 2026
Last enriched4d agov2
Tags
CVE-2026-39836
Trending Score59
Source articles3
Independent3
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-40372EXP
ASP.NET Core Elevation of Privilege Vulnerability
Trending: 61
HIGHCVE-2026-42316EXP
KQL injection via kusto.tables.topics.mapping in kafka-sink-azure-kusto
Trending: 51
HIGHCVE-2026-26164EXP
M365 Copilot Information Disclosure Vulnerability
Trending: 43
HIGHCVE-2026-26129EXP
M365 Copilot Information Disclosure Vulnerability
Trending: 43
CRITICALCVE-2026-33109EXP
Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
Trending: 41

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 7, 2026
Discovered by ZDM
May 7, 2026
Updated: affectedVersions, severity, activelyExploited, cweIds, tags
May 7, 2026
Actively Exploited
May 8, 2026
Patch Available
May 8, 2026

Version History

v2
Last enriched 4d ago
v2Tier C4d ago

Updated affected versions to include 1.25.9 and 1.26.2, changed severity to HIGH, and noted that there is no exploit available.

affectedVersionsseverityactivelyExploitedcweIdstags
via VulDB
v14d ago

Initial creation