Skip to content

Conversation

@witekest
Copy link
Contributor

PR Description

Version v0.45.0 of golang.org/x/net fixes two vulnerabilities in the golang.org/x/net/html package:

  • CVE-2025-47911
  • CVE-2025-58190

Which issue(s) this PR fixes

Notes to the Reviewer

PR Checklist

  • CHANGELOG.md updated
  • Documentation added
  • Tests updated
  • Config converters updated

The change updates golang.org/x/net to version 0.45.0 together with its
dependencies.

Fixes:
* CVE-2025-47911
* CVE-2025-58190
@witekest witekest requested a review from a team as a code owner November 13, 2025 10:35
@jharvey10
Copy link
Contributor

Hi, thanks for the PR!

We have 1.12 coming out in a few days, and it will include moving this module up to v0.45.0, which should resolve both of the CVEs in question.

@witekest
Copy link
Contributor Author

That is good news. Can we keep the request open until 1.12 is released?

@jharvey10
Copy link
Contributor

Yeah, absolutely. Let's keep it open!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants