Skip to content

Update module golang.org/x/net to v0.55.0 [SECURITY] - #36

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/go-golang.org-x-net-vulnerability
Open

Update module golang.org/x/net to v0.55.0 [SECURITY]#36
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/go-golang.org-x-net-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Aug 21, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
golang.org/x/net v0.33.0v0.55.0 age confidence

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

CVE-2025-22870 / GHSA-qxp5-gwg8-xv66

More information

Details

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.

Severity

  • CVSS Score: 4.4 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


golang.org/x/net vulnerable to Cross-site Scripting

CVE-2025-22872 / GHSA-vvgc-356p-c3xw

More information

Details

The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. , , etc contexts).

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Go Net HTML parser is vulnerable to denial of service

CVE-2026-25680 / GHSA-5cv4-jp36-h3mw

More information

Details

In Go Net (golang.org/x/net) before verion 0.55.0, parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

Severity

  • CVSS Score: 6.5 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (in timezone America/Los_Angeles)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) August 21, 2026 17:06
@renovate

renovate Bot commented Aug 21, 2026

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: examples/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 3 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.22.11 -> 1.25.0
golang.org/x/crypto v0.31.0 -> v0.51.0
golang.org/x/sys v0.28.0 -> v0.45.0
golang.org/x/text v0.21.0 -> v0.37.0
File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 3 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.22.11 -> 1.25.0
golang.org/x/crypto v0.31.0 -> v0.51.0
golang.org/x/sys v0.28.0 -> v0.45.0
golang.org/x/text v0.21.0 -> v0.37.0

@github-actions

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ❌ 2 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses.
See the Details below.

Vulnerabilities

examples/go.mod

NameVersionVulnerabilitySeverity
golang.org/x/crypto0.51.0golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responsescritical
golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassedcritical
golang.org/x/crypto vulnerable to infinite loop on large channel writescritical
golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked statuscritical
golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcementcritical
golang.org/x/crypto doesn't enforce invoking key constraintscritical
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keyscritical
golang.org/x/crypto: Invoking byte arithmetic causes underflow and panichigh
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoShigh
golang.org/x/crypto vulnerable to invoking bypass of certificate restrictionsmoderate
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flowmoderate
golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoSmoderate
golang.org/x/crypto: Invoking pathological inputs can lead to client panicmoderate

go.mod

NameVersionVulnerabilitySeverity
golang.org/x/crypto0.51.0golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responsescritical
golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassedcritical
golang.org/x/crypto vulnerable to infinite loop on large channel writescritical
golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked statuscritical
golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcementcritical
golang.org/x/crypto doesn't enforce invoking key constraintscritical
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keyscritical
golang.org/x/crypto: Invoking byte arithmetic causes underflow and panichigh
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoShigh
golang.org/x/crypto vulnerable to invoking bypass of certificate restrictionsmoderate
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flowmoderate
golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoSmoderate
golang.org/x/crypto: Invoking pathological inputs can lead to client panicmoderate

OpenSSF Scorecard

PackageVersionScoreDetails
gomod/golang.org/x/crypto 0.51.0 UnknownUnknown
gomod/golang.org/x/net 0.55.0 UnknownUnknown
gomod/golang.org/x/sys 0.45.0 UnknownUnknown
gomod/golang.org/x/text 0.37.0 UnknownUnknown
gomod/golang.org/x/crypto 0.51.0 UnknownUnknown
gomod/golang.org/x/net 0.55.0 UnknownUnknown
gomod/golang.org/x/sys 0.45.0 UnknownUnknown
gomod/golang.org/x/text 0.37.0 UnknownUnknown

Scanned Files

  • examples/go.mod
  • go.mod

@renovate renovate Bot changed the title Update module golang.org/x/net to v0.55.0 [SECURITY] Update module golang.org/x/net to v0.55.0 [SECURITY] - autoclosed Aug 27, 2026
@renovate renovate Bot closed this Aug 27, 2026
auto-merge was automatically disabled August 27, 2026 00:50

Pull request was closed

@renovate
renovate Bot deleted the renovate/go-golang.org-x-net-vulnerability branch August 27, 2026 00:50
@renovate renovate Bot changed the title Update module golang.org/x/net to v0.55.0 [SECURITY] - autoclosed Update module golang.org/x/net to v0.55.0 [SECURITY] Aug 27, 2026
@renovate renovate Bot reopened this Aug 27, 2026
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch from c5cbc03 to da73ca2 Compare August 27, 2026 06:05
@renovate renovate Bot changed the title Update module golang.org/x/net to v0.55.0 [SECURITY] Update module golang.org/x/net to v0.55.0 [SECURITY] - autoclosed Aug 30, 2026
@renovate renovate Bot closed this Aug 30, 2026
@renovate renovate Bot changed the title Update module golang.org/x/net to v0.55.0 [SECURITY] - autoclosed Update module golang.org/x/net to v0.55.0 [SECURITY] Aug 30, 2026
@renovate renovate Bot reopened this Aug 30, 2026
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch 2 times, most recently from da73ca2 to 075427d Compare August 30, 2026 22:32
@renovate renovate Bot changed the title Update module golang.org/x/net to v0.55.0 [SECURITY] Update module golang.org/x/net to v0.55.0 [SECURITY] - autoclosed Sep 2, 2026
@renovate renovate Bot closed this Sep 2, 2026
| datasource | package          | from    | to      |
| ---------- | ---------------- | ------- | ------- |
| go         | golang.org/x/net | v0.33.0 | v0.55.0 |


Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate Bot changed the title Update module golang.org/x/net to v0.55.0 [SECURITY] - autoclosed Update module golang.org/x/net to v0.55.0 [SECURITY] Sep 2, 2026
@renovate renovate Bot reopened this Sep 2, 2026
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-net-vulnerability branch 2 times, most recently from 075427d to c6cb5da Compare September 2, 2026 11:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants