# OpenFGA v1.20.0

> Security · 2026-09-08

A maintenance release updates the Go toolchain and images to address a security advisory. It also fixes a `ListUsers` deadlock that could cause timeouts with partial results.

## Action needed
- **[security · critical]** Go toolchain and images at go1.26.8
  - The Go toolchain and images are upgraded to use `go1.26.8`, addressing `CVE-2026-39821` and Go advisory `GO-2026-5026`.

## Other recorded changes
- 1 (defect_corrected 1)

[Full analysis](https://ratatosk.io/en/releases/openfga/v1.20.0)

[Original release notes](https://github.com/openfga/openfga/releases/tag/v1.20.0)
