Skip to content

Fix possible fix(deps): 10 vulnerable dependencies in go.mod - #2

Open
begininvoke wants to merge 1 commit into
jvcByte:mainfrom
begininvoke:redgem/security-fix-1a98a9d4
Open

Fix possible fix(deps): 10 vulnerable dependencies in go.mod#2
begininvoke wants to merge 1 commit into
jvcByte:mainfrom
begininvoke:redgem/security-fix-1a98a9d4

Conversation

@begininvoke

Copy link
Copy Markdown

Small change to go.mod — a scan flagged the code below and it looked genuine. It is around line 1.

CVE-2022-41723 affects golang.org/x/net version v0.4.0. A specially crafted HTTP/2 stream can trigger the HPACK decoder to consume excessive CPU, leading to a denial‑of‑service condition even with a few small requests. This high‑severity issue can impact any Go service handling HTTP/2 traffic, making it critical to upgrade. The fix is available in version 0.7.0, which includes mitigations that limit HPACK processing complexity.

Upgrade vulnerable indirect dependencies golang.org/x/net and golang.org/x/text to recent versions that address multiple CVEs.

For reference: rule CVE-2022-41723. Rated high.

I do not know the codebase, so please check the change fits how the rest of it works. Happy to adjust it or close this if the reasoning is off.


Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant