chore(deps): update module golang.org/x/net to v0.45.0 [security]#8
Conversation
|
|
[pr-assist-bot] Pending Owner Approval — Release branch security fix This security dependency update targets The
This is a security fix and should be prioritized. |
PR Assist Bot — Owner Approval NeededThis PR targets release branch PR: AlaudaDevops/harbor-cli#8 Please reply with |
PR Assist Bot AnalysisFailure Type: Dependency Lock File Mismatch |
PR Assist Bot AnalysisStatus: Owner-approved but blocked on |
This PR contains the following updates:
v0.44.0->v0.45.0Infinite parsing loop in golang.org/x/net
CVE-2025-58190 / GO-2026-4441
More information
Details
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
Severity
Unknown
References
This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).
Quadratic parsing complexity in golang.org/x/net/html
CVE-2025-47911 / GHSA-w4gw-w5jq-g9jh / GO-2026-4440
More information
Details
The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
Severity
Unknown
References
This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).
Configuration
📅 Schedule: Branch creation - "" in timezone Asia/Shanghai, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.