Skip to content

[release/v25.2.x] Bump golang.org/x/net to v0.54.0 to address Snyk findings#1508

Open
twmb wants to merge 1 commit intorelease/v25.2.xfrom
tb/backport-snyk-v25.2.x
Open

[release/v25.2.x] Bump golang.org/x/net to v0.54.0 to address Snyk findings#1508
twmb wants to merge 1 commit intorelease/v25.2.xfrom
tb/backport-snyk-v25.2.x

Conversation

@twmb
Copy link
Copy Markdown
Contributor

@twmb twmb commented May 8, 2026

Summary

Backport of #1506 to release/v25.2.x.

Bumps golang.org/x/net to v0.54.0 across all workspace modules to address Snyk-reported HIGH vulnerability.

Vulnerability addressed

HIGH: Infinite loop in golang.org/x/net/http2 — CVE-2026-33814

Notes

  • Snyk currently reports this as "no fix available" but OSV / Go vuln DB show v0.53.0 as the fix release — Snyk DB lag.
  • Stdlib net / net/http findings (CVE-2026-33811, CVE-2026-33814, CVE-2026-39836) require a Go toolchain bump (1.25.7 → 1.25.10) and are tracked separately.

🤖 Generated with Claude Code

Backport of #1506 to release/v25.2.x.

Addresses:
- SNYK-GOLANG-GOLANGORGXNETHTTP2-16535157 / CVE-2026-33814
  Infinite loop in golang.org/x/net/http2
  https://snyk.io/vuln/SNYK-GOLANG-GOLANGORGXNETHTTP2-16535157
  https://pkg.go.dev/vuln/GO-2026-4918

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant