Skip to content

chore(deps): fix vulnerabilities reported by govulncheck#72

Merged
nrwiersma merged 1 commit into
mainfrom
govulncheck/auto-fix
Jun 9, 2026
Merged

chore(deps): fix vulnerabilities reported by govulncheck#72
nrwiersma merged 1 commit into
mainfrom
govulncheck/auto-fix

Conversation

@github-actions

@github-actions github-actions Bot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

Vulnerability Report

stdlibv1.25.11

GO-2025-3955 (CVE-2025-47910, CVE-2025-47910)

CrossOriginProtection insecure bypass patterns not limited to exact matches in net/http

References

GO-2025-4006 (CVE-2025-61725, CVE-2025-61725)

Excessive CPU consumption in ParseAddress in net/mail

References

GO-2025-4007 (CVE-2025-58187, CVE-2025-58187)

Quadratic complexity when checking name constraints in crypto/x509

References

GO-2025-4008 (CVE-2025-58189, CVE-2025-58189)

ALPN negotiation error contains attacker controlled information in crypto/tls

References

GO-2025-4009 (CVE-2025-61723, CVE-2025-61723)

Quadratic complexity when parsing some invalid inputs in encoding/pem

References

GO-2025-4010 (CVE-2025-47912, CVE-2025-47912)

Insufficient validation of bracketed IPv6 hostnames in net/url

References

GO-2025-4011 (CVE-2025-58185, CVE-2025-58185)

Parsing DER payload can cause memory exhaustion in encoding/asn1

References

GO-2025-4012 (CVE-2025-58186, CVE-2025-58186)

Lack of limit when parsing cookies can cause memory exhaustion in net/http

References

GO-2025-4013 (CVE-2025-58188, CVE-2025-58188)

Panic when validating certificates with DSA public keys in crypto/x509

References

GO-2025-4014 (CVE-2025-58183, CVE-2025-58183)

Unbounded allocation when parsing GNU sparse map in archive/tar

References

GO-2025-4015 (CVE-2025-61724, CVE-2025-61724)

Excessive CPU consumption in Reader.ReadResponse in net/textproto

References

GO-2025-4155 (CVE-2025-61729, CVE-2025-61729)

Excessive resource consumption when printing error string for host certificate validation in crypto/x509

References

GO-2025-4175 (CVE-2025-61727)

Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509

References

GO-2026-4337 (CVE-2025-68121)

Unexpected session resumption in crypto/tls

References

GO-2026-4340 (CVE-2025-61730, CVE-2025-61730)

Handshake messages may be processed at the incorrect encryption level in crypto/tls

References

GO-2026-4341 (CVE-2025-61726, CVE-2025-61726)

Memory exhaustion in query parameter parsing in net/url

References

GO-2026-4342 (CVE-2025-61728, CVE-2025-61728)

Excessive CPU consumption when building archive index in archive/zip

References

GO-2026-4601 (CVE-2026-25679)

Incorrect parsing of IPv6 host literals in net/url

References

GO-2026-4602 (CVE-2026-27139)

FileInfo can escape from a Root in os

References

GO-2026-4603 (CVE-2026-27142)

URLs in meta content attribute actions are not escaped in html/template

References

GO-2026-4864 (CVE-2026-32282)

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

References

GO-2026-4865 (CVE-2026-32289)

JsBraceDepth Context Tracking Bugs (XSS) in html/template

References

GO-2026-4869 (CVE-2026-32288)

Unbounded allocation for old GNU sparse in archive/tar

References

GO-2026-4870 (CVE-2026-32283)

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

References

GO-2026-4918 (CVE-2026-33814)

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

References

GO-2026-4946 (CVE-2026-32281)

Inefficient policy validation in crypto/x509

References

GO-2026-4947 (CVE-2026-32280)

Unexpected work during chain building in crypto/x509

References

GO-2026-4971 (CVE-2026-39836)

Panic in Dial and LookupPort when handling NUL byte on Windows in net

References

GO-2026-4976 (CVE-2026-39825)

ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil

References

GO-2026-4977 (CVE-2026-42499)

Quadratic string concatenation in consumePhrase in net/mail

References

GO-2026-4980 (CVE-2026-39826)

Escaper bypass leads to XSS in html/template

References

GO-2026-4981 (CVE-2026-33811)

Crash when handling long CNAME response in net

References

GO-2026-4982 (CVE-2026-39823)

Bypass of meta content URL escaping causes XSS in html/template

References

GO-2026-4986 (CVE-2026-39820)

Quadratic string concatentation in consumeComment in net/mail

References

GO-2026-5037 (CVE-2026-27145)

Inefficient candidate hostname parsing in crypto/x509

References

GO-2026-5038 (CVE-2026-42504)

Quadratic complexity in WordDecoder.DecodeHeader in mime

References

GO-2026-5039 (CVE-2026-42507)

Arbitrary inputs are included in errors without any escaping in net/textproto

References

@github-actions github-actions Bot added dependencies Pull requests that update a dependency file security labels Jun 9, 2026
@nrwiersma nrwiersma closed this Jun 9, 2026
@nrwiersma nrwiersma reopened this Jun 9, 2026
@nrwiersma nrwiersma merged commit abee8b5 into main Jun 9, 2026
7 checks passed
@nrwiersma nrwiersma deleted the govulncheck/auto-fix branch June 9, 2026 05:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security

Development

Successfully merging this pull request may close these issues.

1 participant