Skip to content

Upgrade vcert to use GO version 1.26.2+ to fix vunerabilities #648

@madamorr

Description

@madamorr

PROBLEM SUMMARY
Several CVE's are resolved in later version of GO, specifically 1.26.2
CVE-2025-58185 - fixed in version 1.25.2
CVE-2025-61726 - fixed in version 1.25.6
CVE-2025-58188 - fixed in version 1.25.2
CVE-2025-61724 - fixed in version 1.25.2
CVE-2025-58186 - fixed in version 1.25.2
CVE-2026-32288 - fixed in version 1.26.2
CVE-2025-68121 - fixed in version 1.26.0-rc.3
CVE-2025-61725 - fixed in version 1.25.2
CVE-2025-58187 - fixed in version 1.25.3
CVE-2026-32280 - fixed in version 1.26.2
CVE-2025-58183 - fixed in version 1.25.2
CVE-2025-61723 - fixed in version 1.25.2
CVE-2025-61727 - fixed in version 1.25.5
CVE-2026-32283 - fixed in version 1.26.2
CVE-2026-32280 - fixed in version 1.26.2
CVE-2025-61729 - fixed in version 1.25.5
CVE-2025-58185 - fixed in version 1.25.2
CVE-2026-32288 - fixed in version 1.26.2
CVE-2025-58183 - fixed in version 1.25.2
CVE-2025-61727 - fixed in version 1.25.2
CVE-2025-58186 - fixed in version 1.25.2
CVE-2025-61725 - fixed in version 1.25.2
CVE-2025-58188 - fixed in version 1.25.2
CVE-2025-58187 - fixed in version 1.25.3
CVE-2025-68121 - fixed in version 1.26.0-rc.3
CVE-2025-61723 - fixed in version 1.25.2

Please update to GO version 1.26.2+

STEPS TO REPRODUCE
Our internal scanner identified the vulnerabilities above.

EXPECTED RESULTS
Minimum CVE's for the product.

ACTUAL RESULTS
List of CVE's above.

ENVIRONMENT DETAILS
Amazon AWS

COMMENTS/WORKAROUNDS
None.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions