1. CVE-2026-39822: Go Project - Root escape via symlink plus trailing slash in os
- CVSSv3.1: 7.8 (High)
- Basecamp: Based on the analysis of the vulnerability by the TrendAI development team, it has been confirmed Endpoint Basecamp does use a version of Golang that may be susceptible to the reported issue; however, due to the limited exposure and contained architecture of this module the risk of exploitation is low.
- TrendAI is actively working on an update that will upgrade the Golang runtime to version 1.26.5 or later which will address any potential exploitation of this vulnerability. This patch is expected to be released by early September 2026.
2. GO-2026-6061: Go Project - Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc
- Basecamp: Based on the analysis of the vulnerability by the TrendAI development team, it has been confirmed Endpoint Basecamp is not affected; however, the library is expected to be updated as per regular update maintenance in September 2026.
