Skip to content

CTRL-OS Security Tracker

This is the security tracker for CTRL-OS. It allows monitoring the status of vulnerabilities that affect CTRL-OS releases. Vulnerabilities are ingested from official sources, such as NVD and others.

For general information about installing or upgrading CTRL-OS, refer to the documentation. We are eager to hear your feedback and suggestions for this security tracker. Channels to reach us are documented here.

Releases

These are the currently supported releases.

Latest Events

CVE-2018-13410
CTRL-OS 26.05
zip
Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because
2026-08-17 14:06 CEST
In Progress
The CVE is disputed, but the underlying buffer overflow is real.

CVE-2026-33818
CTRL-OS 26.05
go_1_27
Enforce maximum recursion depth in encoding/asn1
2026-08-17 11:43 CEST
In Progress → Resolved

CVE-2026-56858
CTRL-OS 26.05
go_1_27
Fix Javascript regexp context tracking in html/template
2026-08-17 11:43 CEST
In Progress → Resolved

CVE-2026-39821
CTRL-OS 26.05
go_1_27
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
2026-08-17 11:43 CEST
In Progress → Resolved

CVE-2026-56862
CTRL-OS 26.05
go_1_27
Limit handshake messages we are willing to accept post-handshake in crypto/tls
2026-08-17 11:43 CEST
In Progress → Resolved

CVE-2026-46600
CTRL-OS 26.05
go_1_27
Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
2026-08-17 11:43 CEST
In Progress → Resolved

CVE-2026-56860
CTRL-OS 26.05
go_1_27
Avoid quadratic complexity in resolvePath in net/url
2026-08-17 11:43 CEST
In Progress → Resolved

CVE-2026-56853
CTRL-OS 26.05
go_1_27
Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
2026-08-17 11:43 CEST
In Progress → Resolved

CVE-2026-56859
CTRL-OS 26.05
go_1_27
Add recursion depth guard during decode in encoding/xml
2026-08-17 11:43 CEST
In Progress → Resolved

CVE-2026-56864
CTRL-OS 26.05
go_1_27
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
2026-08-17 11:43 CEST
In Progress → Resolved

CVE-2026-56865
CTRL-OS 26.05
go_1_27
Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
2026-08-17 11:43 CEST
In Progress → Resolved

CVE-2026-33818
CTRL-OS 26.05
go, go_1_26
Enforce maximum recursion depth in encoding/asn1
2026-08-17 11:41 CEST
Resolved → In Progress

CVE-2026-56858
CTRL-OS 26.05
go, go_1_26
Fix Javascript regexp context tracking in html/template
2026-08-17 11:41 CEST
Resolved → In Progress

CVE-2026-39821
CTRL-OS 26.05
go, go_1_26
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
2026-08-17 11:41 CEST
Resolved → In Progress

CVE-2026-56862
CTRL-OS 26.05
go, go_1_26
Limit handshake messages we are willing to accept post-handshake in crypto/tls
2026-08-17 11:41 CEST
Resolved → In Progress

CVE-2026-46600
CTRL-OS 26.05
go, go_1_26
Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
2026-08-17 11:41 CEST
Resolved → In Progress

CVE-2026-56860
CTRL-OS 26.05
go, go_1_26
Avoid quadratic complexity in resolvePath in net/url
2026-08-17 11:41 CEST
Resolved → In Progress

CVE-2026-56853
CTRL-OS 26.05
go, go_1_26
Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
2026-08-17 11:41 CEST
Resolved → In Progress

CVE-2026-56859
CTRL-OS 26.05
go, go_1_26
Add recursion depth guard during decode in encoding/xml
2026-08-17 11:41 CEST
Resolved → In Progress

CVE-2026-56864
CTRL-OS 26.05
go, go_1_26
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
2026-08-17 11:41 CEST
Resolved → In Progress

CVE-2026-56865
CTRL-OS 26.05
go, go_1_26
Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
2026-08-17 11:41 CEST
Resolved → In Progress

CVE-2026-33818
CTRL-OS 26.05
go_1_25
Enforce maximum recursion depth in encoding/asn1
2026-08-17 11:39 CEST
Acknowledged → Resolved
Fixed by updating to Go 1.25.3.

CVE-2026-56858
CTRL-OS 26.05
go_1_25
Fix Javascript regexp context tracking in html/template
2026-08-17 11:39 CEST
Acknowledged → Resolved
Fixed by updating to Go 1.25.3.

CVE-2026-39821
CTRL-OS 26.05
go_1_25
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
2026-08-17 11:39 CEST
Acknowledged → Resolved
Fixed by updating to Go 1.25.3.

CVE-2026-56862
CTRL-OS 26.05
go_1_25
Limit handshake messages we are willing to accept post-handshake in crypto/tls
2026-08-17 11:39 CEST
Acknowledged → Resolved
Fixed by updating to Go 1.25.3.

CVE-2026-46600
CTRL-OS 26.05
go_1_25
Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
2026-08-17 11:39 CEST
Acknowledged → Resolved
Fixed by updating to Go 1.25.3.

CVE-2026-56860
CTRL-OS 26.05
go_1_25
Avoid quadratic complexity in resolvePath in net/url
2026-08-17 11:39 CEST
Acknowledged → Resolved
Fixed by updating to Go 1.25.3.

CVE-2026-56853
CTRL-OS 26.05
go_1_25
Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
2026-08-17 11:39 CEST
Acknowledged → Resolved
Fixed by updating to Go 1.25.3.

CVE-2026-56859
CTRL-OS 26.05
go_1_25
Add recursion depth guard during decode in encoding/xml
2026-08-17 11:39 CEST
Acknowledged → Resolved
Fixed by updating to Go 1.25.3.

CVE-2026-56864
CTRL-OS 26.05
go_1_25
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
2026-08-17 11:39 CEST
Acknowledged → Resolved
Fixed by updating to Go 1.25.3.