Skip to content

Update module golang.org/x/crypto to v0.35.0 [SECURITY]#60

Merged
descope[bot] merged 1 commit intomainfrom
renovate/go-golang.org-x-crypto-vulnerability
Mar 16, 2025
Merged

Update module golang.org/x/crypto to v0.35.0 [SECURITY]#60
descope[bot] merged 1 commit intomainfrom
renovate/go-golang.org-x-crypto-vulnerability

Conversation

@descope
Copy link
Contributor

@descope descope bot commented Mar 16, 2025

This PR contains the following updates:

Package Type Update Change
golang.org/x/crypto indirect minor v0.34.0 -> v0.35.0

Potential denial of service in golang.org/x/crypto

CVE-2025-22869 / GO-2025-3487

More information

Details

SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Configuration

📅 Schedule: Branch creation - "" in timezone Asia/Jerusalem, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@descope descope bot added the security label Mar 16, 2025
@descope descope bot enabled auto-merge (squash) March 16, 2025 18:14
@descope descope bot merged commit 97c3488 into main Mar 16, 2025
2 checks passed
@descope descope bot deleted the renovate/go-golang.org-x-crypto-vulnerability branch March 16, 2025 18:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants