Skip to content

Bump golang.org/x/net to v0.53.0#5242

Merged
pietern merged 1 commit into
mainfrom
x-net-why
May 13, 2026
Merged

Bump golang.org/x/net to v0.53.0#5242
pietern merged 1 commit into
mainfrom
x-net-why

Conversation

@pietern
Copy link
Copy Markdown
Contributor

@pietern pietern commented May 12, 2026

Summary

Clears CVE-2026-33814 (HTTP/2 SETTINGS_MAX_FRAME_SIZE infinite loop) flagged by govulncheck against golang.org/x/net@v0.52.0. Reachable via the Google API transport that the SDK's ID-token credential installs on http.Client.

This pull request and its description were written by Isaac.

Clears CVE-2026-33814 (HTTP/2 SETTINGS_MAX_FRAME_SIZE infinite loop)
flagged by govulncheck against golang.org/x/net@v0.52.0. Reachable via
the Google API transport that the SDK's ID-token credential installs
on http.Client.

Co-authored-by: Isaac
@pietern pietern temporarily deployed to test-trigger-is May 12, 2026 15:25 — with GitHub Actions Inactive
@pietern pietern temporarily deployed to test-trigger-is May 12, 2026 15:25 — with GitHub Actions Inactive
@pietern pietern requested review from denik and simonfaltum May 12, 2026 15:29
@pietern pietern merged commit 5eec9da into main May 13, 2026
29 of 30 checks passed
@pietern pietern deleted the x-net-why branch May 13, 2026 09:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants