-
Notifications
You must be signed in to change notification settings - Fork 18.7k
Closed
Labels
FrozenDueToAgeNeedsInvestigationSomeone must examine and confirm this is a valid issue and not a duplicate of an existing one.Someone must examine and confirm this is a valid issue and not a duplicate of an existing one.
Milestone
Description
x/crypto is currently using version 0.3.6 of golang.org/x/text which has a denial of service vulnerability: https://osv.dev/vulnerability/GO-2021-0113.
I would like to request that x/crypto updates its modules to use version 0.3.7 or higher of golang.org/x/text. Alternatively, if you're confident that x/crypto does not call the vulnerable functions, go ahead and close this issue.
matthewhartstonge
Metadata
Metadata
Assignees
Labels
FrozenDueToAgeNeedsInvestigationSomeone must examine and confirm this is a valid issue and not a duplicate of an existing one.Someone must examine and confirm this is a valid issue and not a duplicate of an existing one.