$ cat golang/week/2026-09-21.log
the week in review · Sep 21 – Sep 27, 2026
Go strips malformed HTTP/2 headers, moves HTTP/3 into std
By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology
The header deletion closes a response-smuggling path; HTTP/3 now lives in an internal std package, cutting repeated vendoring.
net/http/internal/http2: delete malformed framing-related headers golang/go
Historically lax parsing of framing-related headers let the HTTP/2 implementation forward responses it should have rejected. Malformed headers are now dropped rather than passed along, so servers or proxies that relied on the old leniency need to check their framing.
net/http/internal/http3: move HTTP/3 from x/net to std golang/go
The HTTP/3 implementation moves out of x/net into an internal package in std, so development no longer requires repeated vendoring. Practically, HTTP/3 support now tracks the main tree instead of a module you have to pin.
all: use os.Root for handling user input golang/playground
The /compile endpoint accepted an arbitrary txtar, and a malicious one could force writes into the playground host's trusted files. User input now goes through os.Root, which is the same containment pattern you should be applying to untrusted paths in your own services.
simd/archsimd: don't read past the end of the slice in Load*Part golang/go
Dropping LoadMasked* changed the Part loads to read a whole vector and mask afterward, which reads past the end of slices shorter than the vector. If you are on the simd/archsimd API, this is the load semantics fix to pick up.
types2, go/types: prevent nil types in published packages golang/go
Syntax errors, broken cycles, and unresolved types could leave Object.Type(), Alias.fromRHS, Named.fromRHS, or TypeParam.bound nil, and tools traversing the published package graph would panic. Fixed in both go/types and types2, which matters for anything walking type graphs outside the compiler, gopls and linters included.
gopls/internal/cache: clear unloadableFiles on workspace reinit golang/tools
A file that failed to load stayed in snapshot.unloadableFiles until something changed the file itself, so repairing go.mod alone did not clear the mark and MetadataForFile kept skipping it. gopls now clears the set on workspace reinit, which fixes stale inlining and analysis after a module fix.
Revert "cmd/cgo: emit any instead of interface{} in generated files" golang/go
Generating any instead of interface{} in cgo output broke builds, so the change is reverted and interface{} is back in generated files until issue 81648 is resolved. Regenerate or re-vendor if you had already absorbed the rewrite.
compress/flate: speed up writeTokens golang/go
writeTokens now flushes whole bytes from the bit accumulator after every iteration instead of testing whether 48 bits had accumulated, removing a poorly predicted data-dependent branch. Alongside: go/types gained a Scope.Objects iterator with cached Scope.Names, overflowing constants are invalidated instead of left valid for a later unsafe.Pointer assertion, salsa20 and AES decryption picked up...
$ ls golang/week/ # the briefings behind this review
Keep up with Go in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.
fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.
Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.