CVE-2026-42507
When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to
CVSS
5.3
Medium
EPSS
0.4%
p31
KEV
—
Exploit Today
9
0-100
Published: Jun 2, 2026 · Last modified: Jul 22, 2026
0.4%EPSS · 30 days0.4%
2026-08-222026-09-19
When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.
No related CVEs by CWE or product.