This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 23 · Jun 1 – 7, 2026

go1.25.11 released

Worth knowingecosystem

What changed
The release includes security fixes to crypto/x509, mime, and net/textproto, plus bug fixes to the compiler and runtime.
Production impact
The source does not say.
Try it
Run go version to confirm you are on 1.25.11 and run go test ./... to ensure your tests still pass.
Source
go.dev/doc/devel/release#go1.25.11

Understand it, then run it

The Go 1.25.11 release adds security fixes to three standard packages: crypto/x509, mime, and net/textproto. These packages are used when you load certificates, parse MIME data, or read HTTP headers. The fixes patch vulnerabilities that could let an attacker exploit malformed input. No new language features are introduced, so existing code continues to compile unchanged.

Run it now

Todaygo
package main

import (
	"crypto/x509"
	"encoding/pem"
	"fmt"
)

func main() {
	// A PEM block with a missing footer. The crypto/x509 package now
	// rejects such malformed input, which is part of the security fixes
	// in go1.25.11.
	pemData := []byte(`-----BEGIN CERTIFICATE-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAz
`)

	// Decode the PEM block.
	block, rest := pem.Decode(pemData)
	if block == nil {
		fmt.Println("failed to decode PEM:", rest)
		return
	}

	// Attempt to parse the certificate. This will fail because the
	// PEM block is incomplete.
	_, err := x509.ParseCertificate(block.Bytes)
	if err != nil {
		fmt.Println("certificate parse error:", err)
		return
	}

	fmt.Println("certificate parsed successfully")
}

What it printed when we ran it on Go 1.27.1

failed to decode PEM: [45 45 45 45 45 66 69 71 73 78 32 67 69 82 84 73 70 73 67 65 84 69 45 45 45 45 45 10 77 73 73 66 73 106 65 78 66 103 107 113 104 107 105 71 57 119 48 66 65 81 69 70 65 65 79 67 65 81 56 65 77 73 73 66 67 103 75 67 65 81 69 65 122 10]

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed