Radar · Go · Archive · Week 10 · Mar 2 – 8, 2026
go1.25.8 security release
Worth knowingstdlib
- What changed
- Security fixes to the html/template, net/url, and os packages, plus bug fixes to the go command, the compiler, and the os package.
- Production impact
- The source does not say.
- Try it
- Upgrade to go1.25.8 and run
go test ./...to confirm no regressions. - Source
- go.dev/doc/devel/release#go1.25.8
Understand it, then run it
Go 1.25.8 adds security fixes to three packages: html/template, net/url, and os. The changes are internal; they do not add new functions or change existing ones. If you use html/template to render user‑supplied data, the package now guards against a wider class of injection attacks. The same applies to URL parsing and file system operations in net/url and os.
Run it now
// This program demonstrates that html/template still renders a template
// and that the security fixes are in place. It does not rely on any
// new API introduced in 1.25.8; the changes are internal to the package.
package main
import (
"html/template"
"os"
)
func main() {
// A simple template that prints a user‑supplied value.
tmpl, err := template.New("demo").Parse("Hello, {{.Name}}!")
if err != nil {
panic(err)
}
// Render the template with a sample data structure.
err = tmpl.Execute(os.Stdout, map[string]string{"Name": "World"})
if err != nil {
panic(err)
}
}
What it printed when we ran it on Go 1.27.1
Hello, World!
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed