Skip to content

[GHSA-3g75-q268-r9r6] amazon-s3-encryption-client-go/v3: patched in v3.2.0 - #9359

Open
zyl71 wants to merge 1 commit into
github:zyl71/advisory-improvement-9359from
zyl71:fix/GHSA-3g75-q268-r9r6
Open

[GHSA-3g75-q268-r9r6] amazon-s3-encryption-client-go/v3: patched in v3.2.0#9359
zyl71 wants to merge 1 commit into
github:zyl71/advisory-improvement-9359from
zyl71:fix/GHSA-3g75-q268-r9r6

Conversation

@zyl71

@zyl71 zyl71 commented Sep 5, 2026

Copy link
Copy Markdown

Updates

  • Affected products

Comments
The affected product is the /v3 module path, for which a patched version 4.0.0 cannot exist (v4 would be a different module path), so the current range < 4.0.0 marks every v3 release as vulnerable with no upgrade path. The referenced fix commit 3e1740ec014e234e6d454291615011122e642b5d is an ancestor of tag v3.2.0 (Go module version v3.2.0, published 2025-12-16), and the v3.2.0 module zip contains the patched code. Suggested change: affected < 3.2.0, patched 3.2.0.

@github-actions
github-actions Bot changed the base branch from main to zyl71/advisory-improvement-9359 September 5, 2026 04:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant