Skip to content

chore(deps): fix vulnerabilities reported by govulncheck - #344

Merged
nrwiersma merged 1 commit into
mainfrom
govulncheck/auto-fix
Aug 17, 2026
Merged

chore(deps): fix vulnerabilities reported by govulncheck#344
nrwiersma merged 1 commit into
mainfrom
govulncheck/auto-fix

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Vulnerability Report

stdlibv1.25.13

GO-2026-5026 (CVE-2026-39821)

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

References

GO-2026-5972 (CVE-2026-33818)

Enforce maximum recursion depth in encoding/asn1

References

GO-2026-6088 (CVE-2026-56859)

Add recursion depth guard during decode in encoding/xml

References

GO-2026-6089 (CVE-2026-56853)

Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http

References

GO-2026-6090 (CVE-2026-56862)

Limit handshake messages we are willing to accept post-handshake in crypto/tls

References

GO-2026-6091 (CVE-2026-56858)

Fix Javascript regexp context tracking in html/template

References

GO-2026-6218 (CVE-2026-56860)

Avoid quadratic complexity in resolvePath in net/url

References

@github-actions github-actions Bot added dependencies Pull requests that update a dependency file security labels Aug 17, 2026
@nrwiersma
nrwiersma merged commit 3b700dd into main Aug 17, 2026
7 checks passed
@nrwiersma
nrwiersma deleted the govulncheck/auto-fix branch August 17, 2026 05:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security

Development

Successfully merging this pull request may close these issues.

1 participant