Go standard library
net
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
Official registry publication history is available at net, but registry activity is not a publisher support boundary.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2026-46600 | 21 Jul 2026 | 1.26.0-0 < 1.26.6; 1.27.0-0 < 1.27.0-rc.3; < 0.56.0 | Before applying this update, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images are different depending on the installation plan approval policy you used when installing the cert-manager Operator for Red Hat OpenShift. - If the approval policy is set to `Automatic`, then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. - If you changed the approval policy to `Manual`, then you must manually approve the upgrade to the Operator. See https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.html for additional information. | Update reference ↗ |
| CVE-2026-33811 | 7 May 2026 | net: < 1.25.10, 1.26.0-0 < 1.26.3 | RHSA-2026:42079: Red Hat Ansible Automation Platform 2.6 for RHEL 10, Red Hat Ansible Automation Platform 2.6 for RHEL 9 | Update reference ↗ |
| CVE-2026-39836 | 7 May 2026 | < 1.25.10; 1.26.0-0 < 1.26.3 | For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 | Update reference ↗ |
| CVE-2024-24788 | 8 May 2024 | 1.22.0-0 < 1.22.3 | Red Hat Ansible Automation Platform | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.