Commit 9032f6e
Update Go from 1.23.1 to 1.24.7 [security]
The following vulnerabilities were identified by running govulncheck on
the currently latest reproxy binary v0.182.0.8eb62dcb and are addressed
by upgrading Go to the latest 1.24.x version.
We could also upgrade to Go 1.25, but as this version drops support for
older macOS versions, which might still be used by some of our users,
it's better to stick to 1.24.x for now.
Vulnerability #1: GO-2025-3751
Sensitive headers not cleared on cross-origin redirect in net/http
More info: https://pkg.go.dev/vuln/GO-2025-3751
Standard library
Found in: net/[email protected]
Fixed in: net/[email protected]
Vulnerability #2: GO-2025-3750
Inconsistent handling of O_CREATE|O_EXCL on Unix and Windows in os
in syscall
More info: https://pkg.go.dev/vuln/GO-2025-3750
Standard library
Found in: [email protected]
Fixed in: [email protected]
Vulnerability #3: GO-2025-3563
Request smuggling due to acceptance of invalid chunked data in
net/http
More info: https://pkg.go.dev/vuln/GO-2025-3563
Standard library
Found in: net/http/[email protected]
Fixed in: net/http/[email protected]
Vulnerability #4: GO-2025-3447
Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec
More info: https://pkg.go.dev/vuln/GO-2025-3447
Standard library
Found in: crypto/internal/[email protected]
Fixed in: crypto/internal/[email protected]
Vulnerability #5: GO-2025-3420
Sensitive headers incorrectly sent after cross-domain redirect in
net/http
More info: https://pkg.go.dev/vuln/GO-2025-3420
Standard library
Found in: net/[email protected]
Fixed in: net/[email protected]
Vulnerability #6: GO-2025-3373
Usage of IPv6 zone IDs can bypass URI name constraints in
crypto/x509
More info: https://pkg.go.dev/vuln/GO-2025-3373
Standard library
Found in: crypto/[email protected]
Fixed in: crypto/[email protected]
Change-Id: I67b23dd1566a5d5a156ece05630c0e6b50c8eb77
Bug: NA
Test: NA
GitOrigin-RevId: 41e91ef42ed93ebc43fb7a1b5342c37e90fe41ab1 parent 7a9d88b commit 9032f6e
2 files changed
+2
-4
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
119 | 119 | | |
120 | 120 | | |
121 | 121 | | |
122 | | - | |
| 122 | + | |
123 | 123 | | |
124 | 124 | | |
125 | 125 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
4 | | - | |
5 | | - | |
| 3 | + | |
6 | 4 | | |
7 | 5 | | |
8 | 6 | | |
| |||
0 commit comments