diff options
| author | Sharlatan Hellseher <sharlatanus@gmail.com> | 2026-08-17 13:43:51 +0100 |
|---|---|---|
| committer | Sharlatan Hellseher <sharlatanus@gmail.com> | 2026-08-26 14:39:24 +0100 |
| commit | 4a398db65762211316c54289cf090173777e9343 (patch) | |
| tree | f192f3ac9581963af2d693b54797ddfc32c78f56 /gnu/packages/web.scm | |
| parent | e42227e1c7e7055e27cecada52ec801a75e44909 (diff) | |
gnu: go-1.25: Update to 1.25.13 [security-fixes].
go1.25.13 (released 2026-08-13) includes security fixes to the go
command, and the crypto/tls, encoding/asn1, encoding/xml, html/template,
net/http, and net/url packages, as well as bug fixes to the compiler,
the runtime, and the crypto/tls and os packages.
See: <https://github.com/golang/go/milestone/442>,
<https://groups.google.com/g/golang-announce/c/94pEornpRlI>
Contains fixes for:
CVE-2026-56865: x/mod/sumdb/tlog: fix transparency log tile verification
bypass
CVE-2026-56864: x/mod/sumdb: ignore unrelated, unauthenticated hashes in
Lookup
CVE-2026-56859: encoding/xml: add recursion depth guard during decode
CVE-2026-56853: net/http: apply ReadHeaderTimeout when doing unencrypted
HTTP/2 check
CVE-2026-56860: net/url: avoid quadratic complexity in resolvePath
CVE-2026-46600: golang.org/x/net/dns/dnsmessage: panic when parsing
invalid SVCB record
CVE-2026-56862: crypto/tls: limit handshake messages we are willing to
accept post-handshake
CVE-2026-56858: html/template: fix Javascript regexp context tracking
CVE-2026-39821: x/net/idna: failure to reject ASCII-only
Punycode-encoded labels
CVE-2026-33818: encoding/asn1: enforce maximum recursion depth
* gnu/packages/golang.scm (go-1.25): Update to 1.25.13.
Diffstat (limited to 'gnu/packages/web.scm')
0 files changed, 0 insertions, 0 deletions
