Skip to content

chore(deps): fix vulnerabilities reported by govulncheck#340

Merged
nrwiersma merged 1 commit into
mainfrom
govulncheck/auto-fix
Jul 27, 2026
Merged

chore(deps): fix vulnerabilities reported by govulncheck#340
nrwiersma merged 1 commit into
mainfrom
govulncheck/auto-fix

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Vulnerability Report

go.opentelemetry.io/otelv1.44.0

GO-2026-5158 (CVE-2026-41178, GHSA-5wrp-cwcj-q835)

Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel

References

golang.org/x/netv0.56.0

GO-2026-5942 (CVE-2026-46600)

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

References

golang.org/x/textv0.39.0

GO-2026-5970 (CVE-2026-56852)

Infinite loop on invalid input in golang.org/x/text

References

@github-actions github-actions Bot added dependencies Pull requests that update a dependency file security labels Jul 27, 2026
@nrwiersma
nrwiersma merged commit 8ae95dc into main Jul 27, 2026
8 checks passed
@nrwiersma
nrwiersma deleted the govulncheck/auto-fix branch July 27, 2026 08:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security

Development

Successfully merging this pull request may close these issues.

1 participant