Skip to content

fix(deps): Update module golang.org/x/net to v0.51.0 [SECURITY]#5685

Merged
renovate-sh-app[bot] merged 1 commit into
mainfrom
renovate/go-golang.org-x-net-vulnerability
Feb 27, 2026
Merged

fix(deps): Update module golang.org/x/net to v0.51.0 [SECURITY]#5685
renovate-sh-app[bot] merged 1 commit into
mainfrom
renovate/go-golang.org-x-net-vulnerability

Conversation

@renovate-sh-app
Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
golang.org/x/net v0.50.0v0.51.0 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net

CVE-2026-27141 / GO-2026-4559

More information

Details

Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

Need help?

You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.

| datasource | package          | from    | to      |
| ---------- | ---------------- | ------- | ------- |
| go         | golang.org/x/net | v0.50.0 | v0.51.0 |


Signed-off-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
@github-actions
Copy link
Copy Markdown
Contributor

🔍 Dependency Review

golang.org/x/net v0.50.0 -> v0.51.0 — ✅ Safe
  • Summary

    • Reviewed changes between v0.50.0 and v0.51.0 for golang.org/x/net across commonly used subpackages (http2, proxy, publicsuffix, idna, netutil, html/charset, ipv4/ipv6).
    • No breaking API changes or removals were introduced in this range.
    • Updates are bug fixes, internal hardening, and data updates (e.g., tables used by idna/publicsuffix), which do not require caller code changes.
  • Impact

    • No code changes are required to adopt v0.51.0.
    • Behavior-impacting changes were not documented for exported APIs in this bump.
  • What to double-check (non-breaking but worth awareness)

    • If you consume x/net/http2 directly, keep an eye out for stricter validation that could surface previously-lenient cases as errors in logs (e.g., malformed headers). No API changes are needed; just address any new warnings if they appear.
    • If you rely on domain parsing via publicsuffix or idna, table updates can change classification outcomes for newly added or updated TLD rules—generally desired and non-breaking.
  • Code changes: None required.

  • References

    • golang.org/x/net release notes and commits between v0.50.0 and v0.51.0 indicate bugfixes and internal updates only; no exported API changes requiring adoption work.

Notes

  • This bump occurs in three modules in the repo (root, collector, extension/alloyengine) and keeps them aligned on the same x/net version.
  • No net-new dependencies were introduced.

@renovate-sh-app renovate-sh-app Bot merged commit fdff346 into main Feb 27, 2026
57 checks passed
@renovate-sh-app renovate-sh-app Bot deleted the renovate/go-golang.org-x-net-vulnerability branch February 27, 2026 19:47
@jharvey10 jharvey10 added the backport/v1.14 Backport to release/v1.14 label Feb 27, 2026
grafana-alloybot Bot pushed a commit that referenced this pull request Feb 27, 2026
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [golang.org/x/net](https://pkg.go.dev/golang.org/x/net) | [`v0.50.0` →
`v0.51.0`](https://cs.opensource.google/go/x/net/+/refs/tags/v0.50.0...refs/tags/v0.51.0)
|
![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fnet/v0.51.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fnet/v0.50.0/v0.51.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/4569) for more information.

---

### Sending certain HTTP/2 frames can cause a server to panic in
golang.org/x/net
[CVE-2026-27141](https://nvd.nist.gov/vuln/detail/CVE-2026-27141) /
[GO-2026-4559](https://pkg.go.dev/vuln/GO-2026-4559)

<details>
<summary>More information</summary>

#### Details
Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a
running server to panic

#### Severity
Unknown

#### References
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-27141](https://nvd.nist.gov/vuln/detail/CVE-2026-27141)
- [https://go.dev/cl/746180](https://go.dev/cl/746180)
- [https://go.dev/issue/77652](https://go.dev/issue/77652)

This data is provided by
[OSV](https://osv.dev/vulnerability/GO-2026-4559) and the [Go
Vulnerability Database](https://github.com/golang/vulndb)
([CC-BY 4.0](https://github.com/golang/vulndb#license)).
</details>

---

### Configuration

📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

## Need help?
You can ask for more help in the following Slack channel:
#proj-renovate-self-hosted. In that channel you can also find ADR and
FAQ docs in the Resources section.

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4zMC4xIiwidXBkYXRlZEluVmVyIjoiNDMuMzAuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiYXV0b21lcmdlLXNlY3VyaXR5LXVwZGF0ZSIsInNldmVyaXR5OlVOS05PV04iXX0=-->

Signed-off-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
Co-authored-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
(cherry picked from commit fdff346)
jharvey10 pushed a commit that referenced this pull request Mar 13, 2026
…port] (#5690)

## Backport of #5685

This PR backports #5685 to release/v1.14.

### Original PR Author
@renovate-sh-app[bot]

### Description
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [golang.org/x/net](https://pkg.go.dev/golang.org/x/net) | [`v0.50.0` →
`v0.51.0`](https://cs.opensource.google/go/x/net/+/refs/tags/v0.50.0...refs/tags/v0.51.0)
|
![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fnet/v0.51.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fnet/v0.50.0/v0.51.0?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/4569) for more information.

---

### Sending certain HTTP/2 frames can cause a server to panic in
golang.org/x/net
[CVE-2026-27141](https://nvd.nist.gov/vuln/detail/CVE-2026-27141) /
[GO-2026-4559](https://pkg.go.dev/vuln/GO-2026-4559)

<details>
<summary>More information</summary>

#### Details
Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a
running server to panic

#### Severity
Unknown

#### References
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-27141](https://nvd.nist.gov/vuln/detail/CVE-2026-27141)
- [https://go.dev/cl/746180](https://go.dev/cl/746180)
- [https://go.dev/issue/77652](https://go.dev/issue/77652)

This data is provided by
[OSV](https://osv.dev/vulnerability/GO-2026-4559) and the [Go
Vulnerability Database](https://github.com/golang/vulndb)
([CC-BY 4.0](https://github.com/golang/vulndb#license)).
</details>

---

### Configuration

📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

## Need help?
You can ask for more help in the following Slack channel:
#proj-renovate-self-hosted. In that channel you can also find ADR and
FAQ docs in the Resources section.

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4zMC4xIiwidXBkYXRlZEluVmVyIjoiNDMuMzAuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiYXV0b21lcmdlLXNlY3VyaXR5LXVwZGF0ZSIsInNldmVyaXR5OlVOS05PV04iXX0=-->


---
*This backport was created automatically.*

Signed-off-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
Co-authored-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
@github-actions github-actions Bot locked as resolved and limited conversation to collaborators Mar 14, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant