Skip to content

Conversation

@gautambaghel
Copy link
Member

PCI review checklist

  • I have documented a clear reason for, and description of, the change I am making.

  • If applicable, I've documented a plan to revert these changes if they require more than reverting the pull request.

  • If applicable, I've documented the impact of any changes to security controls.

    Examples of changes to security controls include using new access control methods, adding or removing logging pipelines, etc.

@@ -1 +1 @@
1.24.7
1.25.1

Check warning

Code scanning / Go Stdlib Scanner

Quadratic complexity when checking name constraints in crypto/x509 Warning

found OSV reported vulnerability GO-2025-4007 in Go stdlib@1.25.1
@@ -1 +1 @@
1.24.7
1.25.1

Check warning

Code scanning / Go Stdlib Scanner

Parsing DER payload can cause memory exhaustion in encoding/asn1 Warning

found OSV reported vulnerability GO-2025-4011 in Go stdlib@1.25.1
@@ -1 +1 @@
1.24.7
1.25.1

Check warning

Code scanning / Go Stdlib Scanner

ALPN negotiation error contains attacker controlled information in crypto/tls Warning

found OSV reported vulnerability GO-2025-4008 in Go stdlib@1.25.1
@@ -1 +1 @@
1.24.7
1.25.1

Check warning

Code scanning / Go Stdlib Scanner

Unbounded allocation when parsing GNU sparse map in archive/tar Warning

found OSV reported vulnerability GO-2025-4014 in Go stdlib@1.25.1
@@ -1 +1 @@
1.24.7
1.25.1

Check warning

Code scanning / Go Stdlib Scanner

Quadratic complexity when parsing some invalid inputs in encoding/pem Warning

found OSV reported vulnerability GO-2025-4009 in Go stdlib@1.25.1
@@ -1 +1 @@
1.24.7
1.25.1

Check warning

Code scanning / Go Stdlib Scanner

Excessive CPU consumption in ParseAddress in net/mail Warning

found OSV reported vulnerability GO-2025-4006 in Go stdlib@1.25.1
@@ -1 +1 @@
1.24.7
1.25.1

Check warning

Code scanning / Go Stdlib Scanner

Lack of limit when parsing cookies can cause memory exhaustion in net/http Warning

found OSV reported vulnerability GO-2025-4012 in Go stdlib@1.25.1
@@ -1 +1 @@
1.24.7
1.25.1

Check warning

Code scanning / Go Stdlib Scanner

Insufficient validation of bracketed IPv6 hostnames in net/url Warning

found OSV reported vulnerability GO-2025-4010 in Go stdlib@1.25.1
@@ -1 +1 @@
1.24.7
1.25.1

Check warning

Code scanning / Go Stdlib Scanner

Excessive CPU consumption in Reader.ReadResponse in net/textproto Warning

found OSV reported vulnerability GO-2025-4015 in Go stdlib@1.25.1
@@ -1 +1 @@
1.24.7
1.25.1

Check warning

Code scanning / Go Stdlib Scanner

Panic when validating certificates with DSA public keys in crypto/x509 Warning

found OSV reported vulnerability GO-2025-4013 in Go stdlib@1.25.1
@gautambaghel gautambaghel merged commit ecee0a4 into main Nov 19, 2025
31 checks passed
@gautambaghel gautambaghel deleted the fix/repo-update branch November 19, 2025 18:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants