golang-1.26 (1.26.4-1) unstable; urgency=medium * New upstream version 1.26.4 - CVE-2026-27145 crypto/x509: split candidate hostname only once - CVE-2026-42507 net/textproto: escape arbitrary input when including them in errors - CVE-2026-42504 mime: avoid quadratic complexity in WordDecoder.DecodeHeader -- Dr. Tobias Quathamer Thu, 04 Jun 2026 14:35:47 +0200 golang-1.26 (1.26.3-2) unstable; urgency=medium * Support forcing a minimum go compatibility version for GODEBUG via DEB_GOMINCOMPAT. Thanks to Helmut Grohne -- Dr. Tobias Quathamer Thu, 21 May 2026 12:16:31 +0200 golang-1.26 (1.26.3-1) unstable; urgency=medium * New upstream version 1.26.3 - CVE-2026-42501 cmd/go: malicious module proxy can bypass checksum database - CVE-2026-39820 Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations. - CVE-2026-39823 Vulnerability in which URLs were not correctly escaped inside of a tag's attribute. - CVE-2026-33811 When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash. - CVE-2026-39826 If a trusted template author were to write a