CVE-2026-94440: Go Standard Library Mime/multipart
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes.
Affected products
- Go Standard Library Mime/multipart: before 1.26.9 (fixed in 1.26.9); from 1.27.0-0, before 1.27.2 (fixed in 1.27.2)
- Go Standard Library Net/textproto: before 1.26.9 (fixed in 1.26.9); from 1.27.0-0, before 1.27.2 (fixed in 1.27.2)
Published 2026-10-08. Last modified 2026-10-09.