Skip to content

chore(deps): fix vulnerabilities reported by govulncheck#196

Merged
nrwiersma merged 1 commit into
mainfrom
govulncheck/auto-fix
Jun 9, 2026
Merged

chore(deps): fix vulnerabilities reported by govulncheck#196
nrwiersma merged 1 commit into
mainfrom
govulncheck/auto-fix

Conversation

@github-actions

@github-actions github-actions Bot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

Vulnerability Report

golang.org/x/netv0.55.0

GO-2026-5025 (CVE-2026-42506)

Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html

References

GO-2026-5026 (CVE-2026-39821)

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

References

GO-2026-5027 (CVE-2026-42502)

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

References

GO-2026-5028 (CVE-2026-25680)

Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html

References

GO-2026-5029 (CVE-2026-25681)

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

References

GO-2026-5030 (CVE-2026-27136)

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

References

golang.org/x/sysv0.44.0

GO-2026-5024 (CVE-2026-39824)

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

References

stdlibv1.25.11

GO-2026-5037 (CVE-2026-27145)

Inefficient candidate hostname parsing in crypto/x509

References

GO-2026-5038 (CVE-2026-42504)

Quadratic complexity in WordDecoder.DecodeHeader in mime

References

GO-2026-5039 (CVE-2026-42507)

Arbitrary inputs are included in errors without any escaping in net/textproto

References

@github-actions github-actions Bot added dependencies Pull requests that update a dependency file security labels Jun 9, 2026
@nrwiersma nrwiersma closed this Jun 9, 2026
@nrwiersma nrwiersma reopened this Jun 9, 2026
@nrwiersma nrwiersma force-pushed the govulncheck/auto-fix branch from 6737deb to a1b7e09 Compare June 9, 2026 04:52
@nrwiersma nrwiersma merged commit f8cadbd into main Jun 9, 2026
7 checks passed
@nrwiersma nrwiersma deleted the govulncheck/auto-fix branch June 9, 2026 04:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security

Development

Successfully merging this pull request may close these issues.

1 participant