-
Notifications
You must be signed in to change notification settings - Fork 754
Closed
Labels
affects-8.5This bug affects the 8.5.x(LTS) versions.This bug affects the 8.5.x(LTS) versions.severity/majortype/bugThe issue is confirmed as a bug.The issue is confirmed as a bug.
Description
Bug Report
What did you do?
Security audit identified a high-severity vulnerability CVE-2025-30204 in the current project dependency github.com/golang-jwt/jwt.
What did you expect to see?
Update the github.com/golang-jwt/jwt dependency to version 4.5.2 or later.
What did you see instead?
github.com/golang-jwt/jwt v3.2.2+incompatible is in use.
What version of PD are you using (pd-server -V)?
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
affects-8.5This bug affects the 8.5.x(LTS) versions.This bug affects the 8.5.x(LTS) versions.severity/majortype/bugThe issue is confirmed as a bug.The issue is confirmed as a bug.