A vulnerability was found in Google Go up to 1.25.7/1.26.0. It has been rated as critical. This affects the function url.Parse. This manipulation causes improper validation of syntactic correctness of input.

This vulnerability is registered as CVE-2026-25679. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.