Skip to content

Commit 3222f0e

Browse files
authored
[RHOAIENG-17336] - Denial of Service on golang.org/x/net/html (#461)
chore: fix [CVE-2024-45338](https://www.cve.org/CVERecord?id=CVE-2024-45338) - Denial of Service on golang.org/x/net/html Signed-off-by: Spolti <[email protected]>
1 parent e2c9247 commit 3222f0e

File tree

4 files changed

+73
-481
lines changed

4 files changed

+73
-481
lines changed

go.mod

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -115,15 +115,15 @@ require (
115115
go.opentelemetry.io/otel/trace v1.29.0 // indirect
116116
go.uber.org/atomic v1.11.0 // indirect
117117
go.uber.org/multierr v1.11.0 // indirect
118-
golang.org/x/crypto v0.26.0 // indirect
118+
golang.org/x/crypto v0.31.0 // indirect
119119
golang.org/x/exp v0.0.0-20240823005443-9b4947da3948 // indirect
120120
golang.org/x/mod v0.20.0 // indirect
121121
golang.org/x/net v0.28.0 // indirect
122122
golang.org/x/oauth2 v0.22.0 // indirect
123-
golang.org/x/sync v0.8.0 // indirect
124-
golang.org/x/sys v0.24.0 // indirect
125-
golang.org/x/term v0.23.0 // indirect
126-
golang.org/x/text v0.17.0 // indirect
123+
golang.org/x/sync v0.10.0 // indirect
124+
golang.org/x/sys v0.28.0 // indirect
125+
golang.org/x/term v0.27.0 // indirect
126+
golang.org/x/text v0.21.0 // indirect
127127
golang.org/x/time v0.6.0 // indirect
128128
golang.org/x/tools v0.24.0 // indirect
129129
google.golang.org/genproto v0.0.0-20240827150818-7e3bb234dfed // indirect
@@ -140,3 +140,6 @@ require (
140140
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
141141
sigs.k8s.io/structured-merge-diff/v4 v4.4.1 // indirect
142142
)
143+
144+
// Fixes CVE-2024-45338
145+
replace golang.org/x/net => golang.org/x/net v0.33.0

0 commit comments

Comments
 (0)