134 wires and counting

$ follow Go

Keep up with Go in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-07-13
stories 6

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

GO CRYPTO PATCHES SOURCE-ADDRESS VALIDATION BYPASS IN SSH

By RepoJournal · Filed · About Go · Composed from the cited sources · methodology

CVE-2026-46595 closed a critical gap where SSH source-address restrictions weren't enforced consistently across all authentication methods.

The golang/crypto team shipped a fix [1] that extends source-address validation to all authentication callbacks, not just PublicKeyCallback. Previously, VerifiedPublicKeyCallback could return Permissions with CriticalOptions that bypassed the documented enforcement contract. The patch consolidates the check to a single point at the end of each authentication attempt, catching escapes from any auth path. Alongside the security fix, the team hardened the SSH implementation against race conditions [2] in test helpers, corrected channel initialization ordering [3] that could expose zero-valued fields to concurrent goroutines, and made channel.close idempotent [4] using sync.Once to prevent future panics. One thing to note: source-address options are IP-based and will never match non-IP transports like Unix domain sockets [5], a behavior now documented and tested.

Quick answers

What shipped in Go on July 13, 2026?
CVE-2026-46595 closed a critical gap where SSH source-address restrictions weren't enforced consistently across all authentication methods. In total, 6 commits landed.
Who contributed to Go on July 13, 2026?
1 developer shipped this update, including Nicola Murino.
What were the notable Go updates?
ssh: enforce the source-address critical option for all auth callbacks, ssh: fix data race in the doClientServerAuth test helper, and ssh: initialize new channels fully before adding them to chanList.