Skip to content

fix: bump Go toolchain to 1.26.4 to address CVE-2026-42507, CVE-2026-42504, CVE-2026-27145#757

Open
plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/bump-go-toolchain-1-26-4-1748980200000
Open

fix: bump Go toolchain to 1.26.4 to address CVE-2026-42507, CVE-2026-42504, CVE-2026-27145#757
plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/bump-go-toolchain-1-26-4-1748980200000

Conversation

@plural-copilot

@plural-copilot plural-copilot Bot commented Jun 3, 2026

Copy link
Copy Markdown
Contributor

Summary

Bumps the Go toolchain from 1.26.3 → 1.26.4 to remediate three stdlib CVEs identified by Trivy in the usr/local/bin/plural binary embedded in the pluralsh/console image.

CVEs Fixed

CVE Description
CVE-2026-42507 net/textproto: error injection via input reflection
CVE-2026-42504 MIME header CPU exhaustion via invalid encoded-words
CVE-2026-27145 x509.VerifyHostname quadratic CPU via large SAN list

Fix

Upgrade Go toolchain to 1.26.4 in all relevant locations (go.mod, CI workflows, Dockerfiles, Makefile).

Impact

The plural binary produced by this repo is embedded in the pluralsh/console image. Merging and re-releasing this repo will propagate the fix to that image automatically.

@plural-copilot plural-copilot Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR was generated by the codex Plural Agent Runtime. Here's some useful information you might want to know to evaluate the ai's perfomance:

Name Details
💬 Prompt ## Task: Bump Go toolchain from 1.26.3 → 1.26.4 to fix 3 CVEs...
🔗 Run history View run history

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants