A security-focused maintenance release updates the Go toolchain used to build official OPA binaries to address two disclosed standard-library vulnerabilities affecting OPA's HTTP handler and crypto builtins. Users who build their own binaries or images manage the Go version themselves.
Action needed (1)
securitymediumThe
Go 1.build toolchain update26. 4 OPA is built with
Go 1.in this release. The update fixes standard-library vulnerabilities used by OPA's HTTP handler and crypto builtins, identified as26. 4 GO-2026-5037andGO-2026-5039.