chore(all): update module golang.org/x/net to v0.55.0 [SECURITY] - #5649
chore(all): update module golang.org/x/net to v0.55.0 [SECURITY]#5649renovate-bot wants to merge 1 commit into
Conversation
ℹ️ Artifact update noticeFile name: endpoints/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
File name: run/h2c/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
File name: run/testing/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
There was a problem hiding this comment.
Code Review
This pull request updates various Go dependencies, specifically upgrading golang.org/x/net, golang.org/x/sys, golang.org/x/text, and golang.org/x/crypto to newer versions across the endpoints, run/h2c, and run/testing modules. I have no feedback to provide.
This PR contains the following updates:
v0.52.0→v0.55.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Go Net HTML parser is vulnerable to denial of service
CVE-2026-25680 / GHSA-5cv4-jp36-h3mw
More information
Details
In Go Net (
golang.org/x/net) before verion 0.55.0, parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.