Skip to content

Bumping golang to latest version required due to multiple HIGH CVEsΒ #1327

@claudioelefante

Description

@claudioelefante

Vulnerability tools detect multiple HIGH vulnerabilities on golang-migrate v4.19.0

All the following CVEs affects binaries compiled using Go versions before go1.24.8 and from go1.25.0 before go1.25.2:
CVE-2025-47912
CVE-2025-58186
CVE-2025-61723
CVE-2025-58187
CVE-2025-61725
CVE-2025-58188
CVE-2025-61724
CVE-2025-58183

It would be very important to have asap a new version of golang-migrate compiled with the latest available Golang version.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions