Skip to content

Fix CVE-2026-39830, CVE-2026-40898: bump x/crypto, x/net, x/sys, quic-go - #19

Merged
onelapahead merged 1 commit into
release-v0.28.4from
cve-CVE-2026-39830
Jun 30, 2026
Merged

onelapahead merged 1 commit into
release-v0.28.4from
cve-CVE-2026-39830

Conversation

@dwertent

Copy link
Copy Markdown

Bumps:

  • golang.org/x/crypto v0.49.0 -> v0.52.0 (CVE-2026-39830 thru -39834, -42508, -46595 CRITICAL)
  • golang.org/x/net v0.52.0 -> v0.55.0 (CVE-2026-39821 + 5 more HIGH/CRITICAL)
  • golang.org/x/sys v0.42.0 -> v0.45.0 (CVE-2026-39824 UNKNOWN)
  • github.com/quic-go/quic-go v0.59.0 -> v0.59.1 (CVE-2026-40898 HIGH)

Clean fix with go mod tidy - replaces the closed Renovate PRs #17/#18.

…x/sys, quic-go

- golang.org/x/crypto v0.49.0 -> v0.52.0 (fixes CVE-2026-39830 thru -39834, -42508, -46595 CRITICAL)
- golang.org/x/net v0.52.0 -> v0.55.0 (fixes CVE-2026-39821, -25680, -25681, -27136, -42502, -42506)
- golang.org/x/sys v0.42.0 -> v0.45.0 (fixes CVE-2026-39824 UNKNOWN)
- github.com/quic-go/quic-go v0.59.0 -> v0.59.1 (fixes CVE-2026-40898 HIGH)

Signed-off-by: David Wertenteil <david.wertenteil@kaleido.io>
@dwertent
dwertent force-pushed the cve-CVE-2026-39830 branch from 1f16032 to e30eb65 Compare June 29, 2026 16:42
@onelapahead
onelapahead merged commit 3bc3364 into release-v0.28.4 Jun 30, 2026
18 of 20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants