{"id":"SUSE-SU-2026:3830-1","summary":"Security update for go1.27","details":"This update for go1.27 fixes the following issues:\n\n- go1.27.0 (released 2026-08-19) is a major release of Go.\n  go1.27.x minor releases will be provided through August 2027.\n  https://github.com/golang/go/wiki/Go-Release-Cycle\n  go1.27 arrives six months after Go 1.26. Most of its changes are\n  in the implementation of the toolchain, runtime, and\n  libraries. As always, the release maintains the Go 1 promise of\n  compatibility. We expect almost all Go programs to continue to\n  compile and run as before. (bsc#1272545)\n\n  * Language change: Go 1.27 now supports generic methods: a method\n    declaration may declare its own type parameters. This widely\n    anticipated change allows adding generic functions within the\n    namespace of a particular data type where before one had to\n    declare such functions with a scope of the entire package.\n  * Language change: A key in a struct literal may now be any valid\n    field selector for the struct type, not just a (top-level)\n    field name of the struct.\n  * Language change: Function type inference has been generalized\n    to apply in all contexts where a generic function is assigned\n    to a variable of (or converted to) a matching function type.\n  * Tools: Response file (@file) parsing is now supported for the\n    compile, link, asm, cgo, cover, and pack tools. The response\n    file contains whitespace-separated arguments with support for\n    single-quoted and double-quoted strings, escape sequences, and\n    backslash-newline line continuation. The format is compatible\n    with GCC’s response file implementation to ensure\n    interoperability with existing build systems.\n  * go command: The go command no longer has support for the bzr\n    version control system. It will no longer be able to directly\n    fetch modules hosted on bzr servers.\n  * godebug: Starting with Go 1.27, the go command now recognizes a\n    GODEBUG setting for which support was removed (such as\n    asynctimerchan, see below) if it appears in go.mod files\n    (godebug entries) and .go source files (//go:debug\n    comments). It accepts these settings if they are set to the\n    final default value established before the setting was\n    removed. If they are set to an old value, the go command will\n    fail. This change is in the spirit of the Go 1 compatibility\n    guarantee and allows existing programs that set supported\n    GODEBUG settings to continue to build and run without changes\n    even when the respective setting support has been removed.\n  * go test: go test now invokes the stdversion vet check by\n    default. This reports the use of standard library symbols that\n    are too new for the Go version in force in the referring file,\n    as determined by go directive in go.mod and build tags on the\n    file.\n  * go test: go test -json now annotates 'Action':'output' lines\n    with an optional new field 'OutputType', specifying the type of\n    output. Currently, the possible values include “error”,\n    “error-continue”, and “frame”. See cmd/test2json help for\n    details.\n  * go doc: The go doc command now supports package@version syntax,\n    such as go doc example.com/pkg@v1.2.3.\n  * go doc: The go doc command now accepts the -ex command-line\n    option to list executable examples of the given package or\n    symbol. When an example name is passed on the command line\n    (such as go doc bytes.ExampleBuffer), go doc now prints the\n    example source code along with comments.\n  * go fix: The go fix command contains several new modernizers\n    (atomictypes, embedlit, slicesbackward, and unsafefuncs).\n  * go fix: The existing fmtappendf analyzer was removed due to\n    stylistic concerns.\n  * go fix: The existing waitgroup analyzer was renamed to\n    waitgroupgo to avoid ambiguity.\n  * go mod tidy: For modules specifying go 1.27 or later in their\n    go.mod file, go mod tidy now automatically merges duplicate\n    require blocks. This ensures the file maintains a clean,\n    standard structure containing at most two require blocks: one\n    for direct dependencies and one for indirect dependencies.\n  * go mod fix: Existing comment blocks attached to dependencies\n    are preserved during this consolidation. If a comment block is\n    associated with a mixed set of directives (containing both\n    direct and indirect dependencies), the comment block is merged\n    and attached to the new direct dependency block.\n  * go mod fix: Previously, if a go.mod file accumulated multiple\n    disjoint require blocks (often due to manual edits, unresolved\n    Git merge conflicts, or legacy upgrades) go mod tidy would\n    leave the extra blocks intact or inadvertently create new\n    ones. The tool now strictly enforces the two-block layout,\n    consolidating disparate requirements into their respective\n    blocks and cleaning up the structure of the module file\n    automatically.\n  * go tool trace: go tool trace’s -http command-line option now\n    restricts the listen address to localhost when passed only a\n    port (e.g., -http=:6060). This change makes go tool trace\n    consistent with the behavior of go tool pprof’s -http flag. To\n    listen on all addresses, explicitly include the specified\n    address (e.g., -http=0.0.0.0:6060).\n  * runtime: Tracebacks for modules with go directives configuring\n    Go 1.27 or later will now include runtime/pprof goroutine\n    labels in the header line. This behavior can be disabled with\n    tracebacklabels=0 GODEBUG setting (added in Go 1.26). This\n    opt-out is expected to be kept indefinitely in case goroutine\n    labels acquire sensitive information that shouldn’t be made\n    available in tracebacks.\n  * runtime: The asynctimerchan GODEBUG setting (added in Go 1.23)\n    has been removed permanently. Channels created by package time\n    are now always unbuffered (synchronous), irrespective of\n    GODEBUG settings.\n  * runtime: Faster memory allocation. The compiler now generates\n    calls to size-specialized memory allocation routines, reducing\n    the cost of some small (\u003c80 byte) memory allocations by up to\n    30%. Improvements vary depending on the workload, but the\n    overall improvement is expected to be ~1% in real\n    allocation-heavy programs. This causes the binary size to\n    increase by about 60 KB (independent of the workload). Please\n    file an issue if you notice any regressions. You may set\n    GOEXPERIMENT=nosizespecializedmalloc at build time to disable\n    it. This opt-out setting is expected to be removed in Go 1.28.\n  * runtime: Goroutine leak profile. A new profile type that\n    reports leaked goroutines, previously available as an\n    experiment in Go 1.26, is now generally available. The new\n    profile type, named goroutineleak, is supported in the\n    runtime/pprof package. It is also available as the\n    net/http/pprof endpoint /debug/pprof/goroutineleak. A leaked\n    goroutine is a goroutine blocked on some concurrency primitive\n    (channels, sync.Mutex, sync.Cond, etc) that cannot possibly\n    become unblocked. The runtime detects leaked goroutines using\n    the garbage collector: if a goroutine G is blocked on\n    concurrency primitive P, and P is unreachable from any runnable\n    goroutine or any goroutine that those could unblock, then P\n    cannot be unblocked, so goroutine G can never wake up. While it\n    is impossible to detect permanently blocked goroutines in all\n    cases, this approach detects a large class of such\n    leaks. Because this technique builds on reachability, the\n    runtime may fail to identify leaks caused by blocking on\n    concurrency primitives reachable through global variables or\n    the local variables of runnable goroutines. Special thanks to\n    Vlad Saioc at Uber for contributing this work. The\n    goroutineleakprofile GOEXPERIMENT setting is now deleted.\n  * compiler: The compiler now resolves a relative filename in a\n    //line or /*line*/ directive against the directory of the file\n    containing the directive, matching the behavior of\n    go/scanner. Absolute filenames are unaffected. See #70478.\n  * compiler: The compiler now generates simpler names for function\n    literals (closures). Previously, when the containing function\n    is inlined, the function literal’s name can get quite long. Now\n    the compiler chooses the same name for the function literal\n    regardless of inlining. It may also combine multiple instances\n    of the same function literal (as its containing function is\n    inlined) to share the same code in the compiled binary. This\n    change does not affect the functionality of Go code. Tests that\n    check symbol names may need update, although it is recommended\n    to not depend on the names of function literals. For programs\n    that incorrectly compare function code pointer for equality,\n    the issue may be more exposed with Go 1.27, as function\n    literals with different captured closure data may have equal\n    code pointers in more cases.\n  * linker: When targeting macOS, the linker now accepts -macos and\n    -macsdk command-line options, which specify the OS and SDK\n    versions in the LC_BUILD_VERSION load command. By default, it\n    selects the oldest supported macOS version (currently 13.0.0)\n    and a recent SDK version (currently 26.2.0).\n  * Standard library: New encoding/json/v2 and\n    encoding/json/jsontext packages\n  * Standard library: The encoding/json/v2 package is a major\n    revision of encoding/json. It provides Marshal, MarshalWrite,\n    MarshalEncode, Unmarshal, UnmarshalRead, and UnmarshalDecode,\n    all of which accept variadic Options arguments to configure\n    marshaling and unmarshaling behavior. The v2 package chooses\n    stricter, more interoperable defaults than v1: it rejects\n    invalid UTF-8 in JSON strings and rejects duplicate names\n    within a JSON object. See the v1 encoding/json package\n    documentation for the complete set of behavioral differences\n    and the options available to adjust them. Marshal performance\n    is broadly at parity with the previous implementation, while\n    unmarshal performance is significantly faster. Users who\n    encounter compatibility problems with the new implementation\n    may disable it by setting GOEXPERIMENT=nojsonv2 at build time,\n    restoring the original v1 implementation. This opt-out is\n    expected to be removed in a future release.\n  * Standard library: The encoding/json/jsontext package provides\n    lower-level syntactic processing of JSON. The Encoder and\n    Decoder types operate on JSON as a sequence of Token and Value,\n    maintaining a state machine to ensure the produced or consumed\n    sequence is valid JSON text. The encoding/json package is now\n    backed by the v2 implementation. Marshaling and unmarshaling\n    behavior is preserved, but the exact text of error messages may\n    differ. The package also gains a number of new Options that can\n    configure v2 to operate with v1 semantics to avoid requiring a\n    full migration to the new API. The v1 API will continue to be\n    supported and users are not required to migrate. Marshal\n    performance is broadly at parity with the previous\n    implementation, while unmarshal performance is significantly\n    faster.\n  * crypto: The new crypto/mldsa package implements the\n    post-quantum ML-DSA signature scheme specified in FIPS 204.\n  * crypto: crypto/x509 now supports ML-DSA private keys,\n    public keys, and signatures.\n  * crypto: crypto/tls now supports ML-DSA signatures in\n    TLS 1.3, with the new MLDSA44, MLDSA65, and MLDSA87\n    SignatureScheme values.\n  * uuid: The new uuid package generates and parses UUIDs.\n  * simd (experimental): New experimental simd package. Go 1.27\n    introduces a new experimental simd package that provides\n    portable and vector-size-agnostic SIMD support. It will make\n    use of the hardware instructions if they are available. This\n    package is enabled by setting the environment variable\n    GOEXPERIMENT=simd at build time. The simd package is available\n    on all architectures, and provides vector types of unspecified\n    size such as Int8s and Float32s. It supports a “scalable”\n    subset of the operations present in the simd/archsimd package\n    that are hardware-supported or easily emulated across\n    architectures and vector widths.\n  * simd/archsimd (experimental): Go 1.27 continues the\n    experimental support for SIMD operations in the simd/archsimd\n    package that began in Go 1.26. This release revises the amd64\n    API and adds support for arm64 “Neon” 128-bit SIMD and\n    WebAssembly 128-bit SIMD. The simd/archsimd package is enabled\n    by setting the environment variable GOEXPERIMENT=simd at build\n    time. This package provides access to architecture-specific\n    SIMD operations. It supports 128-bit vector types on wasm,\n    arm64, and amd64, and 256-bit and 512-bit vector types on some\n    amd64 processors. The API is not yet considered stable. We\n    intend to provide support for additional architectures in\n    future versions, but the API is intentionally\n    architecture-specific and thus non-portable.\n  * bytes: The new CutLast function slices a []byte around the last\n    occurrence of a separator. It can replace and simplify some\n    common uses of LastIndex.\n  * compress/flate: Compression speed is improved in Go 1.27. The\n    exact encoded output from Writer may be different from Go 1.26\n    as a result of the encoder implementation change. Since DEFLATE\n    is the underlying compression used in archive/zip,\n    compress/gzip, compress/zlib, and image/png, the outputs from\n    those packages may also have changed.\n  * crypto: The new MLDSAMu Hash value is added for use as a\n    signaling mechanism for External mu ML-DSA signing.\n  * crypto/ecdsa: PrivateKey.Sign now checks that the length of the\n    hash is correct, if a non-nil SignerOpts is provided.\n  * crypto/tls: The new QUICConfig.ClientHelloInfoConn field\n    specifies the net.Conn to use for the ClientHelloInfo.Conn\n    field during QUIC server handshakes.\n  * crypto/tls: The MLKEM1024 key exchange is now supported. It can\n    be enabled by adding it to Config.CurvePreferences.\n  * crypto/tls: Config.Rand is now deprecated. For deterministic\n    testing, use testing/cryptotest.SetGlobalRandom.\n  * crypto/tls: Post-quantum hybrid key exchanges can now be\n    explicitly enabled in Config.CurvePreferences even if the\n    tlsmlkem=0 or tlssecpmlkem=0 GODEBUG options are used. Those\n    options were always meant to only apply to the default set used\n    when Config.CurvePreferences is nil.\n  * crypto/tls: The new ConnectionState.LocalCertificate field\n    contains the certificate chain presented to the connection peer\n    during the handshake.\n  * crypto/tls: The tlsunsafeekm (added in Go 1.22), tlsrsakex\n    (added in Go 1.22), tls3des (added in Go 1.23), tls10server\n    (added in Go 1.22), and x509keypairleaf (added in Go 1.23)\n    GODEBUG settings have been removed permanently.\n  * crypto/x509: When parsing into pkix.Name fields, a wider range\n    of pkix.AttributeTypeAndValue.Value types is now supported, and\n    unknown types are parsed into asn1.RawValue.\n  * crypto/x509: The new Certificate.RawSignatureAlgorithm,\n    CertificateRequest.RawSignatureAlgorithm, and\n    RevocationList.RawSignatureAlgorithm fields expose the\n    DER-encoded AlgorithmIdentifier of the signature algorithm,\n    including when the SignatureAlgorithm field is\n    UnknownSignatureAlgorithm.\n  * crypto/x509: SystemCertPool now respects SSL_CERT_FILE and\n    SSL_CERT_DIR on Windows and Darwin. When these environment\n    variables are set, roots are loaded from disk and instead of\n    using the platform certificate verification APIs, the native Go\n    verifier is used. This behavior can be disabled with\n    GODEBUG=x509sslcertoverrideplatform=0.\n  * crypto/x509/pkix: RDNSequence.String (and therefore\n    Name.String) now renders string-typed attribute values as\n    strings even when the attribute’s OID is\n    unrecognized. Previously such values were always hex-encoded in\n    their DER form. See #33093.\n  * database/sql: The new ConvertAssign function gives database\n    drivers access to the type conversions performed by Rows.Scan.\n  * database/sql/driver: Drivers may implement the new\n    RowsColumnScanner interface to scan directly into user-provided\n    destinations.\n  * go/constant: The new StringLen function returns the length of a\n    string Value without fully constructing the Value.\n  * go/scanner: The scanner now allows retrieving the end position\n    of a token via the new Scanner.End method.\n  * go/token: File now has a String method.\n  * go/types: The Hasher type is an implementation of\n    maphash.Hasher for Types that respects the Identical\n    equivalence relation, allowing Types to be used in hash tables\n    and similar data structures. HasherIgnoreTags is the analogous\n    hasher for IdenticalIgnoreTags.\n  * go/types: The gotypesalias GODEBUG setting (added in Go 1.22)\n    has been removed permanently and the package go/types now\n    always produces an Alias type node for alias declarations\n    irrespective of GODEBUG settings.\n  * hash/maphash: The Hasher interface type defines the contract\n    between values of a particular type and future hash-based data\n    structures such as hash tables and Bloom filters; see #70471.\n  * hash/maphash: The ComparableHasher type provides a convenient\n    implementation of Hasher for comparable types where the Equal\n    method is defined as ==.\n  * math/big: Int now has a Divide method to compute quotient and\n    remainder of two Int values. It supports rounding modes Trunc,\n    Floor, Round, and Ceil.\n  * math/rand/v2: Rand now supports a generic method N, matching\n    the behavior of the top-level N function.\n  * net: UnixConn read methods now return io.EOF directly instead\n    of wrapping it in net.OpError when the underlying read returns\n    EOF.\n  * net/http: Transport and Server support TLS ALPN protocol\n    negotiation on user-provided net.Conn connections which\n    implement a ConnectionState() tls.ConnectionState method.\n  * net/http: HTTP/2 server now accepts client priority signals, as\n    defined in RFC 9218, allowing it to prioritize serving HTTP/2\n    streams with higher priority. If the old behavior is preferred,\n    where streams are served in a round-robin manner regardless of\n    priority, Server.DisableClientPriority can be set to true.\n  * net/http: HTTP/1 Response.Body now automatically drains any\n    unread content upon being closed, up to a conservative limit,\n    to allow better connection reuse. For most programs, this\n    change should be a no-op, or result in a performance\n    improvement. In rare cases, programs that do not benefit from\n    connection reuse might experience performance degradation if\n    they had been improperly allowing an excessive amount of idle\n    connections to linger; usually by setting\n    Transport.MaxIdleConns to 0 or using different Clients for\n    different requests, thereby bypassing Transport.MaxIdleConns\n    limit. In these cases, setting Transport.DisableKeepAlives to\n    true will disable connection reuse. However, such performance\n    degradation usually indicates improper configuration or usage\n    of Transport or Client in the first place, and a deeper look\n    would likely be beneficial.\n  * net/http: The new Server.MaxHeaderValueCount field allows HTTP\n    servers to control the number of header values that they are\n    willing to accept. If unset, DefaultMaxHeaderValueCount is\n    used.\n  * net/http/httptest: The new NewTestServer function creates a\n    Server configured to use an in-memory fake network suitable for\n    use with the testing/synctest package.\n  * net/url: The new URL.Clone method creates a deep copy of a\n    URL. The new Values.Clone method creates a deep copy of Values.\n  * runtime/secret: Goroutines that are created while in secret\n    mode will now themselves execute in secret mode.\n  * strings: The new CutLast function slices a string around the\n    last occurrence of a separator. It can replace and simplify\n    some common uses of LastIndex.\n  * syscall: On Plan 9, the Errno type is now defined and\n    implements the error interface, as on other platforms. Plan 9\n    system calls return ErrorString values, so Errno is never\n    returned by this package on Plan 9. It is defined so that\n    portable code referring to syscall.Errno builds on Plan 9\n    without build constraints.\n  * testing/synctest: The new Sleep helper function combines\n    time.Sleep and synctest.Wait.\n  * unicode: The unicode package and associated support throughout\n    the system have been upgraded from Unicode 15 to Unicode\n    17. See the Unicode 16.0.0 and Unicode 17.0.0 release notes for\n    information about the changes.\n  * Ports: Darwin: As announced in the Go 1.26 release notes, Go\n    1.27 requires macOS 13 Ventura or later; support for previous\n    versions has been discontinued.\n  * Ports: PowerPC: On the big-endian 64-bit PowerPC port on Linux\n    (GOOS=linux GOARCH=ppc64), the Go toolchain now generates\n    binaries that use the ELFv2 system ABI. ELFv2 support requires\n    Linux kernel 3.13 or later. RHEL7 backported this support to\n    its 3.10 kernel.\n  * Ports: PowerPC: Cgo, position-independent executables (PIE),\n    and external linking are now supported. Using these features\n    requires an ELFv2 compatible runtime (libc and all linked and\n    loaded libraries).\n  * Ports: PowerPC: For programs that do not use cgo, the Go\n    toolchain still generates static binaries with internal linking\n    by default. For programs that have cgo options, if a static,\n    pure-Go binary is needed, one can set the environment variable\n    CGO_ENABLED=0 when running go build.\n\n- CVE-2026-56853 CVE-2026-39821 CVE-2026-56862 CVE-2026-56859 CVE-2026-56860 CVE-2026-56865 CVE-2026-56864 CVE-2026-33818 CVE-2026-56858\n\n  * go#80205 bsc#1275028 security: fix CVE-2026-56853 net/http: apply ReadHeaderTimeout when doing unencrypted HTTP/2 check\n  * go#78760 bsc#1266609 security: fix CVE-2026-39821 x/net/idna: failure to reject ASCII-only Punycode-encoded labels\n  * go#80528 bsc#1275032 security: fix CVE-2026-56862 crypto/tls: limit handshake messages we are willing to accept post-handshake\n  * go#80481 bsc#1275026 security: fix CVE-2026-56859 encoding/xml: add recursion depth guard during decode\n  * go#80494 bsc#1275029 security: fix CVE-2026-56860 net/url: avoid quadratic complexity in resolvePath\n  * go#80744 bsc#1275024 security: fix CVE-2026-56865 x/mod/sumdb/tlog: fix transparency log tile verification bypass\n  * go#80745 bsc#1275025 security: fix CVE-2026-56864 x/mod/sumdb: ignore unrelated, unauthenticated hashes in Lookup\n  * go#80405 bsc#1275034 security: fix CVE-2026-33818 encoding/asn1: enforce maximum recursion depth\n  * go#80435 bsc#1275033 security: fix CVE-2026-56858 html/template: fix Javascript regexp context tracking\n","modified":"2026-08-31T18:23:12.027500291Z","published":"2026-08-26T14:07:25Z","related":["CVE-2026-33818","CVE-2026-39821","CVE-2026-56853","CVE-2026-56858","CVE-2026-56859","CVE-2026-56860","CVE-2026-56862","CVE-2026-56864","CVE-2026-56865"],"upstream":["CVE-2026-33818","CVE-2026-39821","CVE-2026-56853","CVE-2026-56858","CVE-2026-56859","CVE-2026-56860","CVE-2026-56862","CVE-2026-56864","CVE-2026-56865"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263830-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266609"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272545"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275024"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275025"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275026"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275028"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275029"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275032"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275033"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275034"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33818"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56853"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56858"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56859"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56860"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56862"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56864"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56865"}],"affected":[{"package":{"name":"go1.27","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP7","purl":"pkg:rpm/suse/go1.27&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.27.0-150000.1.6.1"}]}],"ecosystem_specific":{"binaries":[{"go1.27":"1.27.0-150000.1.6.1","go1.27-doc":"1.27.0-150000.1.6.1","go1.27-race":"1.27.0-150000.1.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3830-1.json"}},{"package":{"name":"go1.27","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/go1.27&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.27.0-150000.1.6.1"}]}],"ecosystem_specific":{"binaries":[{"go1.27":"1.27.0-150000.1.6.1","go1.27-doc":"1.27.0-150000.1.6.1","go1.27-race":"1.27.0-150000.1.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3830-1.json"}},{"package":{"name":"go1.27","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/go1.27&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.27.0-150000.1.6.1"}]}],"ecosystem_specific":{"binaries":[{"go1.27":"1.27.0-150000.1.6.1","go1.27-doc":"1.27.0-150000.1.6.1","go1.27-race":"1.27.0-150000.1.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3830-1.json"}},{"package":{"name":"go1.27","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/go1.27&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.27.0-150000.1.6.1"}]}],"ecosystem_specific":{"binaries":[{"go1.27-race":"1.27.0-150000.1.6.1","go1.27":"1.27.0-150000.1.6.1","go1.27-doc":"1.27.0-150000.1.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3830-1.json"}},{"package":{"name":"go1.27","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/go1.27&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.27.0-150000.1.6.1"}]}],"ecosystem_specific":{"binaries":[{"go1.27":"1.27.0-150000.1.6.1","go1.27-doc":"1.27.0-150000.1.6.1","go1.27-race":"1.27.0-150000.1.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3830-1.json"}},{"package":{"name":"go1.27","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/go1.27&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.27.0-150000.1.6.1"}]}],"ecosystem_specific":{"binaries":[{"go1.27":"1.27.0-150000.1.6.1","go1.27-doc":"1.27.0-150000.1.6.1","go1.27-race":"1.27.0-150000.1.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3830-1.json"}},{"package":{"name":"go1.27","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/go1.27&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.27.0-150000.1.6.1"}]}],"ecosystem_specific":{"binaries":[{"go1.27-doc":"1.27.0-150000.1.6.1","go1.27-race":"1.27.0-150000.1.6.1","go1.27":"1.27.0-150000.1.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3830-1.json"}},{"package":{"name":"go1.27","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/go1.27&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.27.0-150000.1.6.1"}]}],"ecosystem_specific":{"binaries":[{"go1.27-doc":"1.27.0-150000.1.6.1","go1.27-race":"1.27.0-150000.1.6.1","go1.27":"1.27.0-150000.1.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3830-1.json"}},{"package":{"name":"go1.27","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/go1.27&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.27.0-150000.1.6.1"}]}],"ecosystem_specific":{"binaries":[{"go1.27":"1.27.0-150000.1.6.1","go1.27-doc":"1.27.0-150000.1.6.1","go1.27-race":"1.27.0-150000.1.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3830-1.json"}},{"package":{"name":"go1.27","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/go1.27&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.27.0-150000.1.6.1"}]}],"ecosystem_specific":{"binaries":[{"go1.27":"1.27.0-150000.1.6.1","go1.27-doc":"1.27.0-150000.1.6.1","go1.27-race":"1.27.0-150000.1.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3830-1.json"}},{"package":{"name":"go1.27","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/go1.27&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.27.0-150000.1.6.1"}]}],"ecosystem_specific":{"binaries":[{"go1.27-race":"1.27.0-150000.1.6.1","go1.27":"1.27.0-150000.1.6.1","go1.27-doc":"1.27.0-150000.1.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3830-1.json"}}],"schema_version":"1.9.0"}