https://seclists.org/oss-sec/2026/q1/68: Go 1.25.6 and Go 1.24.12 aleased with 6 CVE fixes
Published Jan 15, 2026
·Updated
Affected Software
1 affected component
golang/go
Frequently Asked Questions
1
What are the CVE fixes included in Go 1.25.6 and Go 1.24.12?
Go 1.25.6 and Go 1.24.12 include six security fixes, addressing vulnerabilities in their respective libraries.
2
How do I update to Go 1.25.6 or Go 1.24.12?
You can update to Go 1.25.6 or Go 1.24.12 by downloading the latest version from the official Go programming language website.
3
What does the denial of service vulnerability in archive/zip entail?
The denial of service vulnerability in archive/zip allows an attacker to cause a crash in applications parsing malicious ZIP archives.
4
Is the denial of service vulnerability in Go versions critical?
The denial of service vulnerability in the affected Go versions is considered serious due to its potential impact on application availability.
5
What is the release date for Go 1.25.6 and Go 1.24.12?
Go 1.25.6 and Go 1.24.12 were released on January 15, 2026.