Go 1.x — End of Life

Active High risk
17 releases in this series187 CVEs

Go 1.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatus
1.26Feb 11, 2026No1.26.4Active
1.25Aug 12, 2025No1.25.11Active
1.24Feb 11, 2025Feb 11, 20261.24.13EOL
1.23Aug 13, 2024Aug 12, 20251.23.12EOL
1.22Feb 6, 2024Feb 11, 20251.22.12EOL
1.21Aug 8, 2023Aug 13, 20241.21.13EOL
1.20Feb 1, 2023Feb 6, 20241.20.14EOL
1.19Aug 2, 2022Sep 6, 20231.19.13EOL
1.18Mar 15, 2022Feb 1, 20231.18.10EOL
1.17Aug 16, 2021Aug 2, 20221.17.13EOL
1.16Feb 16, 2021Mar 15, 20221.16.15EOL
1.15Aug 11, 2020Aug 16, 20211.15.15EOL
1.14Feb 25, 2020Feb 16, 20211.14.15EOL
1.13Sep 3, 2019Aug 11, 20201.13.15EOL
1.12Feb 25, 2019Feb 25, 20201.12.17EOL
1.11Aug 24, 2018Sep 3, 20191.11.13EOL
1.10Feb 16, 2018Feb 25, 20191.10.8EOL

CVEs affecting Go 1.x (187)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-33811HIGH7.50.02%1.12When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33811HIGH7.50.02%1.25When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33811HIGH7.50.02%1.24When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33811HIGH7.50.02%1.23When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33811HIGH7.50.02%1.22When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33811HIGH7.50.02%1.21When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33811HIGH7.50.02%1.20When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33811HIGH7.50.02%1.19When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33811HIGH7.50.02%1.18When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33811HIGH7.50.02%1.17When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33811HIGH7.50.02%1.16When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33811HIGH7.50.02%1.15When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33811HIGH7.50.02%1.14When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33811HIGH7.50.02%1.13When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33811HIGH7.50.02%1.11When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33811HIGH7.50.02%1.10When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33811HIGH7.50.02%1.26When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.25When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.24When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.23When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.22When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.21When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.20When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.19When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.18When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.17When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.16When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.15When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.14When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.13When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.12When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.11When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.10When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-33814HIGH7.50.02%1.26When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.16Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.25Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.24Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.23Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.22Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.21Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.20Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.19Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.18Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.17Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.15Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.14Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.13Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.12Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.11Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.10Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39820HIGH7.50.06%1.26Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion…May 7, 2026
CVE-2026-39836HIGH7.50.02%1.25The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-39836HIGH7.50.02%1.24The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-39836HIGH7.50.02%1.23The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-39836HIGH7.50.02%1.22The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-39836HIGH7.50.02%1.21The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-39836HIGH7.50.02%1.20The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-39836HIGH7.50.02%1.19The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-39836HIGH7.50.02%1.18The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-39836HIGH7.50.02%1.17The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-39836HIGH7.50.02%1.16The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-39836HIGH7.50.02%1.15The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-39836HIGH7.50.02%1.14The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-39836HIGH7.50.02%1.13The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-39836HIGH7.50.02%1.12The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-39836HIGH7.50.02%1.11The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-39836HIGH7.50.02%1.10The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-39836HIGH7.50.02%1.26The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).May 7, 2026
CVE-2026-42499HIGH7.50.02%1.25Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42499HIGH7.50.02%1.24Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42499HIGH7.50.02%1.23Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42499HIGH7.50.02%1.22Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42499HIGH7.50.02%1.21Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42499HIGH7.50.02%1.20Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42499HIGH7.50.02%1.19Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42499HIGH7.50.02%1.18Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42499HIGH7.50.02%1.17Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42499HIGH7.50.02%1.16Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42499HIGH7.50.02%1.15Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42499HIGH7.50.02%1.14Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42499HIGH7.50.02%1.13Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42499HIGH7.50.02%1.12Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42499HIGH7.50.02%1.11Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42499HIGH7.50.02%1.10Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42499HIGH7.50.02%1.26Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.May 7, 2026
CVE-2026-42501HIGH7.50.01%1.25A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-42501HIGH7.50.01%1.24A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-42501HIGH7.50.01%1.23A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-42501HIGH7.50.01%1.22A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-42501HIGH7.50.01%1.21A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-42501HIGH7.50.01%1.20A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-42501HIGH7.50.01%1.19A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-42501HIGH7.50.01%1.18A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-42501HIGH7.50.01%1.17A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-42501HIGH7.50.01%1.16A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-42501HIGH7.50.01%1.15A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-42501HIGH7.50.01%1.14A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-42501HIGH7.50.01%1.13A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-42501HIGH7.50.01%1.12A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-42501HIGH7.50.01%1.11A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-42501HIGH7.50.01%1.10A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-42501HIGH7.50.01%1.26A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.25CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.26If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.10If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.11If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.12If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.13If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.14If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.15If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.16If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.17If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.19If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.20If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.21If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.22If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.23If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.24If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.25If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.26CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.10CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.11CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.12CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.13CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.14CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.15CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.16CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39826MEDIUM6.10.01%1.18If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.17CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.18CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.19CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.20CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.21CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.22CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.24CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39823MEDIUM6.10.01%1.23CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.10The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.25The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.24The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.23The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.22The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.21The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.20The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.19The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.18The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.17The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.16The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.15The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.14The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.13The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.12The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.11The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39817MEDIUM5.90.01%1.26The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.26The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.10The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.11The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.12The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.13The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.14The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.15The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.16The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.17The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.18The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.19The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.20The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.26ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.21The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.22The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.23The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.24The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39819MEDIUM5.30.01%1.25The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.25ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.10ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.11ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.12ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.13ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.14ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.15ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.16ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.17ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.18ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.19ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.20ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.21ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.22ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.23ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026
CVE-2026-39825MEDIUM5.30.01%1.24ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi…May 7, 2026

Frequently asked questions

Is Go 1 end of life?

Partially. Some Go 1.x releases have reached EOL. Check the version table above for the exact status of each sub-release.

What CVEs affect Go 1?

There are 187 CVEs tracked for Go 1.x. See the full list above with CVSS and EPSS scores.

What is the latest Go 1 version?

The latest Go 1.x patch release is 1.26.4, released on June 2, 2026. Always run the latest patch to benefit from all security fixes.

When was Go 1 first released?

Go 1.0 was initially released on February 11, 2026. See the full version timeline in the table above.

Is it safe to run Go 1 in production?

Go 1 is still supported and safe for production use. Ensure you are running the latest patch version (1.26.4) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA