Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Mar 11, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
golang.org/x/oauth2 v0.18.0 -> v0.27.0 age adoption passing confidence
golang.org/x/oauth2 v0.6.0 -> v0.27.0 age adoption passing confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Unexpected memory consumption during token parsing in golang.org/x/oauth2

CVE-2025-22868 / GO-2025-3488

More information

Details

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested review from a team as code owners March 11, 2025 11:17
@renovate renovate bot added the security label Mar 11, 2025
@renovate renovate bot requested review from GenPage, lukemassa and nitrocode and removed request for a team March 11, 2025 11:17
@renovate renovate bot enabled auto-merge (squash) March 11, 2025 11:17
@github-actions github-actions bot added the dependencies PRs that update a dependency file label Mar 11, 2025
auto-merge was automatically disabled March 13, 2025 17:32

Pull request was closed

@renovate renovate bot deleted the renovate/release-0.31-go-golang.org-x-oauth2-vulnerability branch March 13, 2025 17:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies PRs that update a dependency file security
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants