A vulnerability was found in gopls up to 0.21.x on Go. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to binding to an unrestricted ip address.
This vulnerability is registered as CVE-2026-42503. The attack requires access to the local network. No exploit is available.
It is recommended to upgrade the affected component.