This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 19 · May 4 – 10, 2026

go1.26.3 security and bug fixes

Worth knowingecosystem

What changed
The release includes security fixes to the go command, the pack tool, and the html/template, net, net/http, net/http/httputil, net/mail, and syscall packages, as well as bug fixes to the go command, the go fix command, the compiler, the linker, the runtime, and the crypto/fips140, crypto/tls, go/types, and os packages.
Production impact
The source does not say.
Try it
Update a Go 1.26.x installation to 1.26.3 and run go test ./... to confirm that existing tests still pass.
Source
go.dev/doc/devel/release#go1.26.3

Understand it, then run it

The Go 1.26.3 release brings a set of security fixes that affect several core packages. The changes are limited to bug patches, not new language features, so the syntax you use stays the same. The packages touched include html/template, net, net/http, net/http/httputil, net/mail, and syscall, as well as tools like the go command and the pack tool. The fixes also touch the runtime, compiler, and linker, but those are internal and invisible to most developers.

Run it now

Todaygo
package main

// This program demonstrates that Go 1.26.3 has been released with security fixes
// to several core packages. The program itself does not use any new features
// and simply prints a confirmation message. The changes are internal and
// do not affect the code shown here.

import "fmt"

func main() {
    fmt.Println("Go 1.26.3 is installed and running.")
}

What it printed when we ran it on Go 1.27.1

Go 1.26.3 is installed and running.

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed