Skip to content

Patch vulnerabilities for xcrypto - #32

Merged
def merged 1 commit into
coroot:mainfrom
infor7:crypto-vuln-patching
Jul 30, 2026
Merged

Patch vulnerabilities for xcrypto#32
def merged 1 commit into
coroot:mainfrom
infor7:crypto-vuln-patching

Conversation

@infor7

@infor7 infor7 commented Jul 29, 2026

Copy link
Copy Markdown

xcrypto are vulnerable to following CVE:
CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39835, CVE-2026-46597, CVE-2026-46598

Fix is provided in 0.52.0

xcrypto 0.52.0 requires golang 1.25, so it has been upgraded as well. Debian bullseye do not have golang 1.25, so that one needs to be upgraded to bookworm.

@def
def merged commit b3c1643 into coroot:main Jul 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants