Skip to content

fix: Upgrade filippo.io/edwards25519 to v1.2.0 for CVE-2026-26958#389

Open
tbphp wants to merge 1 commit intomainfrom
fix/upgrade-edwards25519
Open

fix: Upgrade filippo.io/edwards25519 to v1.2.0 for CVE-2026-26958#389
tbphp wants to merge 1 commit intomainfrom
fix/upgrade-edwards25519

Conversation

@tbphp
Copy link
Owner

@tbphp tbphp commented Feb 24, 2026

关联 Issue / Related Issue

Closes https://github.com/tbphp/gpt-load/security/dependabot/17

变更内容 / Change Content

  • Bug 修复 / Bug fix
  • 新功能 / New feature
  • 其他改动 / Other changes

升级间接依赖 filippo.io/edwards25519 从 v1.1.0 到 v1.2.0,修复 CVE-2026-26958GHSA-fw7p-63qq-7hpr)安全漏洞。

Upgrade indirect dependency filippo.io/edwards25519 from v1.1.0 to v1.2.0 to fix CVE-2026-26958 (GHSA-fw7p-63qq-7hpr) security vulnerability. The vulnerability causes MultiScalarMult to produce invalid results when receiver is not the identity point.

自查清单 / Checklist

  • 我已在本地测试过我的变更。 / I have tested my changes locally.
  • 我已更新了必要的文档。 / I have updated the necessary documentation.

@tbphp tbphp self-assigned this Feb 24, 2026
@tbphp tbphp added the bug Something isn't working label Feb 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant