freenode
Languages & Toolchains

Go 1.27.2 and 1.26.9 due Thursday with 10 private CVEs

Minor releases will ship standard-library security fixes under the project's usual pre-announcement policy.

The Go team plans to issue Go 1.27.2 and Go 1.26.9 during US business hours on Thursday, October 8, carrying private security fixes in the standard library.

The releases address ten CVE-listed flaws: CVE-2026-97032, CVE-2026-78659, CVE-2026-97031, CVE-2026-94440, CVE-2026-56866, CVE-2026-94439, CVE-2026-78669, CVE-2026-56857, CVE-2026-78667, and CVE-2026-78663. Details remain private ahead of the builds, consistent with Go's security policy of pre-announcing minor releases that contain undisclosed fixes.

Anyone running Go 1.27 or 1.26 should plan to upgrade once the binaries are published. The pre-announcement gives operators a short window to schedule the update without exposing exploit specifics early.