logo

Go Programming Language 1.26 Patches Several Security Flaws

ID: a33d0f7f-236f-532d-83cc-132941c13267

STIX ID: report--a33d0f7f-236f-532d-83cc-132941c13267

Feed Name: TechRepublic Security

Threat Score
70/100

Date Published: 2026-01-16

Date Updated: 2026-04-23

Author: TechRepublic Staff

...
...

The Go project released Go 1.25.6 and Go 1.24.12 to fix six vulnerabilities affecting archive/zip, net/http, crypto/tls and the Go toolchain; issues include CPU/memory exhaustion (DoS) via crafted ZIP files and large form payloads, TLS session/handshake handling flaws, and toolchain defects that could enable arbitrary code execution during module fetching or builds. Organizations that process untrusted archives/forms or run CI/build systems should upgrade promptly to mitigate availability, session-security, and supply-chain risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.