Skip to content

Bump golang.org/x/net to resolve GO-2026-4559#37063

Closed
bircni wants to merge 1 commit intogo-gitea:mainfrom
bircni:fix/GO-2026-4559
Closed

Bump golang.org/x/net to resolve GO-2026-4559#37063
bircni wants to merge 1 commit intogo-gitea:mainfrom
bircni:fix/GO-2026-4559

Conversation

@bircni
Copy link
Copy Markdown
Member

@bircni bircni commented Mar 31, 2026

Upgrade golang.org/x/net to a patched release that fixes GO-2026-4559 (HTTP/2 server panic) and align golang.org/x/crypto and golang.org/x/sys with that release’s required versions.

Refer to:

Vulnerability #1: GO-2026-4559
    Sending certain HTTP/2 frames can cause a server to panic in
    golang.org/x/net
  More info: https://pkg.go.dev/vuln/GO-2026-4559
  Module: golang.org/x/net
    Found in: golang.org/x/net@v0.50.0

@GiteaBot GiteaBot added the lgtm/need 2 This PR needs two approvals by maintainers to be considered for merging. label Mar 31, 2026
@silverwind
Copy link
Copy Markdown
Member

All these bumps are already included in #37060.

@silverwind silverwind closed this Mar 31, 2026
@bircni bircni deleted the fix/GO-2026-4559 branch March 31, 2026 22:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lgtm/need 2 This PR needs two approvals by maintainers to be considered for merging. modifies/dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants