VEXID-6017414
Published 2026-06-02 23:16:38
Last Modified 2026-06-02 23:16:38
AKA CVE-2026-42507
Summary When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.
CVSS
Access Vector Local Adjacent Network
Access Complexity Low Medium High
Authentication None Single Multiple
Confidentiality None Partial Complete
Integrity None Partial Complete
Availability None Partial Complete