https://seclists.org/oss-sec/2026/q1/147: Go 1.25.7 and Go 1.24.13 aleased with 2 CVE fixes
Published Feb 7, 2026
·Updated
Affected Software
1 affected component
golang/go
Frequently Asked Questions
1
What is the severity of CVE-XXXX-XXXX in Go 1.25.7 and Go 1.24.13?
The severity of CVE-XXXX-XXXX is classified as high due to potential exposure to user content in document strings.
2
How do I fix CVE-XXXX-XXXX in Go 1.25.7 and Go 1.24.13?
To fix CVE-XXXX-XXXX, upgrade your Go installation to version 1.25.7 or 1.24.13.
3
Are there any additional features in Go 1.25.7 and Go 1.24.13 besides CVE fixes?
Go versions 1.25.7 and 1.24.13 primarily focus on security fixes rather than new features.
4
What are the implications of the CVE fixes in Go 1.25.7 and Go 1.24.13?
The implications of the CVE fixes involve enhanced security by removing user content exposure from cgo ASTs.
5
When were Go versions 1.25.7 and 1.24.13 released?
Go versions 1.25.7 and 1.24.13 were released on February 7, 2026.