Go
GO PATCHES TEMPLATE INJECTION FLAW, HTTP/2 GOROUTINE LEAK
Go shipped a security fix for html/template that blocks JavaScript regexp injection attacks, while simultaneously addressing a goroutine accumulation bug in HTTP/2 transports that could exhaust memory on long-lived connections.
read --wire →