$ cat golang/week/2026-09-28.log
the week in review · Sep 28 – Oct 4, 2026
Go toolchain patches three CVEs in module and template verification
By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology
html/template and x/net/http2 both ship breaking security fixes, while Go 1.27's JSON v1 shim restores a field callers depend on.
html/template: reset JS context for template expressions golang/go
Every template expression that starts with a regular expression now gets regexp escaping, closing a context-confusion hole in generated JS. This is the CVE-2026-94448 fix, and it changes output for templates that previously relied on the old escaping, so re-check any template that emits JavaScript.
http2: delete malformed framing-related headers golang/net
The x/net backport of the same fix for CVE-2026-78660 deletes framing-related headers that arrive malformed instead of trusting them. It is a breaking behavior change: peers that previously got through will now have those headers stripped rather than passed along.
net/http: add nethttpomithttp2server and nethttpomithttp2client build tags golang/go
nethttpomithttp2 removed both HTTP/2 client and server; the new nethttpomithttp2server and nethttpomithttp2client tags let you drop just one. Any program using http.Server links in the HTTP/2 server even if it never serves HTTP/2, so a binary that only needs the client can now shed the server side.
encoding/json: fix UnsupportedValueError.Value regression golang/go
In Go 1.27, where v1 is implemented on top of v2, UnsupportedValueError.Value stopped being populated; the compatibility shim now fills it. If your error reporting or tests read that field, they work again without a downgrade.
cmd/internal/pgo: accept CPU profiles from external tools like Linux perf golang/go
PGO previously rejected anything but Go's own runtime/pprof value types ("samples"/"count" and "cpu"/"nanoseconds"). FromPProf now accepts CPU profiles from external tools such as Linux perf, so profiles collected outside the Go toolchain are usable as PGO input.
go/ssa, cmd/deadcode: release type information once functions are built golang/tools
Every ssa.Function held a pointer to its package's types.Info, keeping the Info of every package alive for the life of the Program. Releasing that reference once functions are built cuts memory for tools like cmd/deadcode that build a whole program.
cmd/compile: optimize offset+base memory access lowering rules on loong64 golang/go
Where an offset exceeds 12 bits in offset+base accesses, MOV{W,V}P's larger 16-bit immediate field can be used instead of materializing the offset, reducing instruction count on loong64. Architecture-specific, but it lands in the compiler you already build with.
types2, go/types: fix data race in Unalias on alias instances golang/go
When a generic alias is instantiated through types.Instantiate outside package checking, newAliasInstance runs with a nil Checker and Unalias raced. Anyone calling types.Instantiate on generic aliases from analysis tooling should pick up this fix.
$ ls golang/week/ # the briefings behind this review
Keep up with Go in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.
fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.
Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.