HomeDefault status
unaffected
Any version before 1.25.11
affected
1.26.0-0 (semver) before 1.26.4
affected
Description
When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.
Problem types
CWE-532: Insertion of Sensitive Information into Log File
Product status
Any version before 1.25.11
1.26.0-0 (semver) before 1.26.4
References
groups.google.com/g/golang-announce/c/tKs3rmcBcKw