Skip to content

Conversation

@prkalle
Copy link
Contributor

@prkalle prkalle commented Jan 23, 2026

Description of the Change

GHSA-7c64-f9jr-v9h2 (GO-2025-4155) is a high-severity vulnerability affecting Go versions < 1.24.11 and 1.25.0-1.25.4. The vulnerability causes excessive resource consumption in printing error strings for host certificate validation.

This commit updates the Go version from 1.25.4 to 1.25.5, which includes the fix for this CVE.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-61729

Why Is This PR Valuable?

This PR addresses a security issue in TLS when incorrect / spoofed certificate is used.

Applicable Issues

List any applicable GitHub Issues here

How Urgent Is The Change?

Given the CVSS score of 7.5 (High), a fix is needed asap.

Other Relevant Parties

None

)

CVE-2025-61729 (GO-2025-4155) is a high-severity vulnerability affecting
Go versions < 1.24.11 and 1.25.0-1.25.4. The vulnerability causes
excessive resource consumption in printing error strings for host
certificate validation.

This commit updates the Go version from 1.25.4 to 1.25.5, which includes
the fix for this CVE.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-61729
Copy link
Contributor

@anujc25 anujc25 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants