Skip to content

v1.3.8 - Security Updates

Latest
Compare
Choose a tag to compare
@adlio adlio released this 19 Jul 06:10
· 13 commits to main since this release

Changes in v1.3.8

  • Update golang.org/x/crypto to v0.40.0 to address security vulnerabilities
  • Update golang.org/x/net to v0.42.0 to address security vulnerabilities

This release addresses several security vulnerabilities in dependencies:

  1. Fixed critical and high severity issues in golang.org/x/crypto:

    • Misuse of ServerConfig.PublicKeyCallback that could cause authorization bypass
    • Denial of Service (DoS) vulnerability via Slow or Incomplete Key Exchange
  2. Fixed medium severity issues in golang.org/x/net:

    • Cross-site Scripting vulnerability
    • HTTP Proxy bypass using IPv6 Zone IDs