Archive · Week 19 · May 4 – 10, 2026from 6 items
This week the Go team released two security‑focused point releases, 1.25.10 and 1.26.3, and accepted several proposals that extend cryptographic support and clarify API documentation. The releases address vulnerabilities in core tools and packages, while the proposals add ML‑DSA and MLKEM support to the TLS stack and expose raw signature algorithm data in X.509 certificates.
Worth knowingecosystem
go1.25.10 security and bug fixes
- What changed
- The release includes security fixes to the go command, the pack tool, and the html/template, net, net/http, net/http/httputil, net/mail, and syscall packages, as well as bug fixes to the go command, the compiler, the linker, the runtime, and the crypto/fips140, go/types, and os packages.
- Production impact
- The source does not say.
- Try it
- Run
go versionafter updating to 1.25.10 and verify that the command line tools work as before. - Source
- go.dev/doc/devel/release#go1.25.10
Explain it and run it
Understand it, then run it
The Go 1.25.10 release adds security fixes to several core packages. It patches the go command, the pack tool, and the html/template, net, net/http, net/http/httputil, net/mail, and syscall packages. Bug fixes are also applied to the go command, the compiler, the linker, the runtime, and the crypto/fips140, go/types, and os packages. These changes are part of the normal maintenance cycle that keeps the language safe and reliable.
Run it now
// This program demonstrates that the standard library packages referenced in the
// security fix list (e.g., os, net, html/template) are available and can be
// imported and used in Go 1.27.1. It prints a simple message using the os
// package to show that the import works without any errors.
package main
import (
"fmt"
"os"
)
func main() {
// Use os.Args to access command-line arguments and print them.
fmt.Println("Command-line arguments:", os.Args)
}
What it printed when we ran it on Go 1.27.1
Command-line arguments: [/work/prog]
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingecosystem
go1.26.3 security and bug fixes
- What changed
- The release includes security fixes to the go command, the pack tool, and the html/template, net, net/http, net/http/httputil, net/mail, and syscall packages, as well as bug fixes to the go command, the go fix command, the compiler, the linker, the runtime, and the crypto/fips140, crypto/tls, go/types, and os packages.
- Production impact
- The source does not say.
- Try it
- Update a Go 1.26.x installation to 1.26.3 and run
go test ./...to confirm that existing tests still pass. - Source
- go.dev/doc/devel/release#go1.26.3
Explain it and run it
Understand it, then run it
The Go 1.26.3 release brings a set of security fixes that affect several core packages. The changes are limited to bug patches, not new language features, so the syntax you use stays the same. The packages touched include html/template, net, net/http, net/http/httputil, net/mail, and syscall, as well as tools like the go command and the pack tool. The fixes also touch the runtime, compiler, and linker, but those are internal and invisible to most developers.
Run it now
package main
// This program demonstrates that Go 1.26.3 has been released with security fixes
// to several core packages. The program itself does not use any new features
// and simply prints a confirmation message. The changes are internal and
// do not affect the code shown here.
import "fmt"
func main() {
fmt.Println("Go 1.26.3 is installed and running.")
}
What it printed when we ran it on Go 1.27.1
Go 1.26.3 is installed and running.
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Nice to knowecosystem
crypto/x509: add Certificate.RawSignatureAlgorithm
- What changed
- The proposal adds a
RawSignatureAlgorithm []bytefield tocrypto/x509.Certificate,CertificateRequest, andRevocationList. - Production impact
- The source does not say.
- Try it
- Parse an X.509 certificate with an unknown signature algorithm and inspect the
RawSignatureAlgorithmfield. - Source
- github.com/golang/go/issues/76133
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates the new RawSignatureAlgorithm field in
// crypto/x509.Certificate. It is not yet available in Go 1.27.1, so the
// program simply shows how the field would be used once the change ships.
package main
import (
"crypto/x509"
"fmt"
)
func main() {
// A DER-encoded AlgorithmIdentifier for a hypothetical signature algorithm.
// In practice this would come from parsing a real certificate.
alg := []byte{0x30, 0x0a, 0x06, 0x08, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b}
// Create a Certificate with the raw algorithm bytes set.
cert := &x509.Certificate{
RawSignatureAlgorithm: alg,
}
// Print the raw algorithm bytes to confirm the field is populated.
fmt.Printf("RawSignatureAlgorithm: %x\n", cert.RawSignatureAlgorithm)
}
What it printed when we ran it on Go 1.27.1
RawSignatureAlgorithm: 300a06082a864886f70d01010b
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Nice to knowecosystem
go/importer: clarification of ForCompiler lookup parameter
- What changed
- Documentation of the lookup parameter of
ForCompilercan be clarified to correct a parsing bug that caused unintended deprecation. - Production impact
- The source does not say.
- Try it
- Run
go doc go/importer.ForCompilerand verify that the documentation now reflects the intended behavior. - Source
- github.com/golang/go/issues/79139
Explain it
Understand it, then run it
The ForCompiler function in the go/importer package lets you load Go packages by name, using the compiler’s view of the source tree. A recent change clarified the documentation for its lookup argument. Previously the docs were ambiguous and a parsing bug caused the function to be marked as deprecated in Go 1.16, even though it was still fully usable. The clarification removes that confusion and restores the function’s normal status.
Exercise
Write a small program that parses an X.509 certificate from a PEM file and prints the raw signature algorithm bytes.
The 60-second version
Hello, and welcome to this week’s Go Radar. The Go team has just released two point releases, 1.25.10 and 1.26.3, both of which focus on tightening security across core tools and packages. They patch vulnerabilities in the go command, the pack tool, and several standard library packages, and they also fix bugs in the compiler, linker, runtime, and cryptographic libraries. In addition, the team has accepted several proposals that broaden cryptographic support. One adds ML‑DSA signatures to the TLS and X.509 packages, another introduces a new key‑exchange algorithm, MLKEM1024, into TLS, and a third exposes the raw signature algorithm bytes in parsed certificates. There’s also a small but useful clarification to the importer’s ForCompiler function documentation. These changes mean that your builds and services should stay up to date with the latest security patches, and that you’ll soon be able to work with newer post‑quantum cryptography primitives in Go’s standard library.
Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed