
Go 1.26.5, 1.25.12 fix 2 CVEs https://www.openwall.com/lists/oss-security/2026/07/08/10 CVE-2026-39822: os: Root escape via symlink plus trailing slash CVE-2026-42505: crypto/tls: Encrypted Client Hello privacy leak
Post summary
This notice announces that Go 1.26.5 and 1.25.12 contain patches for CVE‑2026‑39822 and CVE‑2026‑42505, encouraging users to update to the fixed versions.

