From be42e1b46d3cfa2d9d967572f948d96c2da61bb9 Mon Sep 17 00:00:00 2001 From: Dmitry Lopatin <93423466+LopatinDmitr@users.noreply.github.com> Date: Wed, 13 May 2026 16:48:32 +0300 Subject: [PATCH 1/3] chore(core): cve mitigation 11-05-2026 (#2340) - Fix CVE-2026-29181: OpenTelemetry-Go: multi-value baggage header extraction causes excessive allocations (remote dos amplification) - Fix CVE-2026-33811: When using LookupCNAME with the cgo DNS resolver, a very long CNAME... - Fix CVE-2026-33814: When processing HTTP/2 SETTINGS frames, transport will enter an infini ... - Fix CVE-2026-39820: Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ... - Fix CVE-2026-39823: CVE-2026-27142 fixed a vulnerability in which URLs were not correctly ... - Fix CVE-2026-39825: ReverseProxy can forward queries containing parameters not visible to ... - Fix CVE-2026-39826: If a trusted template author were to write a