A vulnerability was found in Go standard library url up to 1.25.12/1.26.5 and classified as problematic . Affected by this issue is some unknown functionality of the component Path Resolution . Such manipulation leads to inefficient algorithmic complexity. This vulnerability is listed as CVE-2026-56860 . The attack may be performed from remote. There is no available exploit. It is suggested to upgrade the affected component.