
Go 1.26.5, 1.25.12 fix 2 CVEs https://www.openwall.com/lists/oss-security/2026/07/08/10 CVE-2026-39822: os: Root escape via symlink plus trailing slash CVE-2026-42505: crypto/tls: Encrypted Client Hello privacy leak
Post summary
Go has released version 1.26.5 (and 1.25.12) with patches that resolve CVE‑2026‑39822 (root escape via symlink + trailing slash) and CVE‑2026‑42505 (Encrypted Client Hello privacy leak).
