Skip to content

chore(deps): bump Go to 1.26.3#32

Merged
babs merged 1 commit into
masterfrom
chore/bump-go-1.26.3
May 20, 2026
Merged

chore(deps): bump Go to 1.26.3#32
babs merged 1 commit into
masterfrom
chore/bump-go-1.26.3

Conversation

@babs

@babs babs commented May 20, 2026

Copy link
Copy Markdown
Owner

Patches stdlib CVEs reachable from current code:

  • GO-2026-4982, GO-2026-4980: html/template escaper bypass XSS (renderConsent in handlers/consent.go)
  • GO-2026-4976: net/http/httputil ReverseProxy query-param forwarding
  • GO-2026-4971: net Dial NUL-byte panic (Windows)
  • GO-2026-4918: net/http HTTP/2 SETTINGS_MAX_FRAME_SIZE infinite loop

Dockerfile builder digest refreshed to a 1.26-alpine image that resolves to 1.26.3.

Patches stdlib CVEs reachable from current code:
- GO-2026-4982, GO-2026-4980: html/template escaper bypass XSS
  (renderConsent in handlers/consent.go)
- GO-2026-4976: net/http/httputil ReverseProxy query-param forwarding
- GO-2026-4971: net Dial NUL-byte panic (Windows)
- GO-2026-4918: net/http HTTP/2 SETTINGS_MAX_FRAME_SIZE infinite loop

Dockerfile builder digest refreshed to a 1.26-alpine image that
resolves to 1.26.3.
@babs babs merged commit 8baabdf into master May 20, 2026
7 checks passed
@babs babs deleted the chore/bump-go-1.26.3 branch May 20, 2026 18:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant