Releases: openshift-sustaining/net
Release list
v0.50.0-sec.4 fixes CVE-2026-27136 for Go 1.24.0
release-v0.50.0-sec.4
Upstream: https://go.dev/cl/781685
What's Changed
- [Go 1.24.0] CVE-2026-27136: html: ignore duplicate attributes during tokenization by @germanparente in #12
Full Changelog: v0.50.0-sec.3...v0.50.0-sec.4
v0.43.0-sec.4 fixes CVE-2026-27136 for Go 1.23.0
release-v0.43.0-sec.4
Upstream: https://go.dev/cl/781685
What's Changed
- [Go 1.23] CVE-2026-27136: html: ignore duplicate attributes during tokenization by @germanparente in #13
Full Changelog: v0.43.0-sec.3...v0.43.0-sec.4
v0.35.0-sec.4 fixes CVE-2026-27136 for Go 1.18
release-v0.35.0-sec.4
Upstream: https://go.dev/cl/781685
What's Changed
- [Go 1.18] CVE-2026-27136: html: ignore duplicate attributes during tokenization by @germanparente in #14
Full Changelog: v0.35.0-sec.3...v0.35.0-sec.4
v0.50.0-sec.3 fixes CVE-2026-33814 for Go 1.24.0
release-v0.50.0-sec.3
Upstream: https://go.dev/cl/761640
What's Changed
- [Go 1.24.0] CVE-2026-33814: http2: prevent hanging Transport due to bad SETTINGS frame by @jkaurredhat in #9
Full Changelog: v0.50.0-sec.2...v0.50.0-sec.3
v0.43.0-sec.3 fixes CVE-2026-33814 for Go 1.23.0
CVE: CVE-2026-33814
Upstream: https://go.dev/cl/761640
What's Changed
- [Go 1.23.0] CVE-2026-33814: http2: prevent hanging Transport due to bad SETTINGS frame by @jkaurredhat in #10
Full Changelog: v0.43.0-sec.2...v0.43.0-sec.3
v0.35.0-sec.3 fixes CVE-2026-33814 for Go 1.18
CVE: CVE-2026-33814
Upstream: https://go.dev/cl/761640
What's Changed
- [Go 1.18] CVE-2026-33814: http2: prevent hanging Transport due to bad SETTINGS frame by @black-dragon74 in #7
Full Changelog: v0.35.0-sec.2...v0.35.0-sec.3
v0.50.0-sec.2 fixes CVE-2026-25681 for Go v1.24
What's Changed
- [Go 1.24.0] CVE-2026-25681: html: escape greater-than symbol in doctype identifiers by @Atharva-Shinde in #4
Full Changelog: v0.50.0-sec.1...v0.50.0-sec.2
v0.43.0-sec.2 fixes CVE-2026-25681 for Go v1.23
What's Changed
- [Go 1.23.0] CVE-2026-25681: html: escape greater-than symbol in doctype identifiers by @Atharva-Shinde in #5
Full Changelog: v0.43.0-sec.1...v0.43.0-sec.2
v0.35.0-sec.2 fixes CVE-2026-25681 for Go v1.18
What's Changed
- [Go v1.18] CVE-2026-25681: html: escape greater-than symbol in doctype identifiers by @Atharva-Shinde in #6
Full Changelog: v0.35.0-sec.1...v0.35.0-sec.2
v0.50.0-sec.1 fixes CVE-2026-39821 for Go v1.24
What's Changed
- [Go v1.24] CVE-2026-39821: idna: reject all-ASCII xn-- labels on all Go versions by @Atharva-Shinde in #1
Full Changelog: https://github.com/openshift-sustaining/net/commits/v0.50.0-sec.1