CVE-2026-42507
Received Received - Intake
Textproto Package Error Message Injection Vulnerability

Publication date: 2026-06-02

Last updated on: 2026-06-02

Assigner: Go Project

Description
When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-02
Last Modified
2026-06-02
Generated
2026-06-03
AI Q&A
2026-06-03
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability occurs in the net/textproto package where functions return errors that include the input data as part of the error message.

Because the input is included in the error, an attacker might be able to inject misleading or malicious content into these error messages that are printed or logged.


How can this vulnerability impact me? :

The vulnerability can allow an attacker to inject misleading content into error messages that are printed or logged.

This could cause confusion or misinterpretation of logs or error outputs, potentially hiding real issues or causing incorrect responses based on the misleading information.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart