Skip to content

Backport of CVE Fix into release/1.20.x#22270

Closed
hc-github-team-consul-core wants to merge 2 commits into
release/1.20.xfrom
backport/nitin/cve-fix/singularly-present-gibbon
Closed

Backport of CVE Fix into release/1.20.x#22270
hc-github-team-consul-core wants to merge 2 commits into
release/1.20.xfrom
backport/nitin/cve-fix/singularly-present-gibbon

Conversation

@hc-github-team-consul-core
Copy link
Copy Markdown
Collaborator

Backport

This PR is auto-generated from #22268 to be assessed for backporting due to the inclusion of the label backport/1.20.

The below text is copied from the body of the original PR.


Fixed following CVEs:
GHSA-vvgc-356p-c3xw in golang.org/x/net@v0.37.0
GO-2025-3595 in golang.org/x/net@v0.37.0
GO-2025-3553 in github.com/golang-jwt/jwt/v4@v4.5.1 GHSA-mh63-6h87-95cp in github.com/golang-jwt/jwt/v4@v4.5.1 stdlib in Go GO-2025-3563@1.23.7

Description

Testing & Reproduction steps

Links

PR Checklist

  • updated test coverage
  • external facing docs updated
  • appropriate backport labels added
  • not a security concern

Overview of commits

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Consul Bot automated PR

@github-actions github-actions Bot added theme/api Relating to the HTTP API interface pr/dependencies PR specifically updates dependencies of project labels Apr 17, 2025
@github-actions github-actions Bot deleted the backport/nitin/cve-fix/singularly-present-gibbon branch October 15, 2025 06:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr/dependencies PR specifically updates dependencies of project theme/api Relating to the HTTP API interface

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants