Go 1.26 Released With Fixes for Multiple Vulnerabilities Causing Memory Exhaustion
ID: f34d1e5a-2972-5a44-a35b-0616f1820747
STIX ID: report--f34d1e5a-2972-5a44-a35b-0616f1820747
Feed Name: GBHackers
The Go project released minor point updates (1.25.6 and 1.24.12) addressing six security vulnerabilities across archive/zip, net/http, crypto/tls, and cmd/go that enable denial-of-service, memory exhaustion, session resumption/authentication bypass, and arbitrary/remote code execution (CVE-2025-61728, CVE-2025-61726, CVE-2025-68121, CVE-2025-61731, CVE-2025-68119, CVE-2025-61730). Key issues include ParseForm memory exhaustion, a super-linear ZIP indexing DoS, TLS Config.Clone copying session ticket keys and failing to validate full chain expiration, and toolchain flaws allowing unsanitized flags and VCS-induced code execution; developers are urged to apply updates immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
