Radar · Go · Archive · Week 19 · May 4 – 10, 2026
go1.26.3 security and bug fixes
Worth knowingecosystem
- What changed
- The release includes security fixes to the go command, the pack tool, and the html/template, net, net/http, net/http/httputil, net/mail, and syscall packages, as well as bug fixes to the go command, the go fix command, the compiler, the linker, the runtime, and the crypto/fips140, crypto/tls, go/types, and os packages.
- Production impact
- The source does not say.
- Try it
- Update a Go 1.26.x installation to 1.26.3 and run
go test ./...to confirm that existing tests still pass. - Source
- go.dev/doc/devel/release#go1.26.3
Understand it, then run it
The Go 1.26.3 release brings a set of security fixes that affect several core packages. The changes are limited to bug patches, not new language features, so the syntax you use stays the same. The packages touched include html/template, net, net/http, net/http/httputil, net/mail, and syscall, as well as tools like the go command and the pack tool. The fixes also touch the runtime, compiler, and linker, but those are internal and invisible to most developers.
Run it now
package main
// This program demonstrates that Go 1.26.3 has been released with security fixes
// to several core packages. The program itself does not use any new features
// and simply prints a confirmation message. The changes are internal and
// do not affect the code shown here.
import "fmt"
func main() {
fmt.Println("Go 1.26.3 is installed and running.")
}
What it printed when we ran it on Go 1.27.1
Go 1.26.3 is installed and running.
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed