[Git][security-tracker-team/security-tracker][master] Track fixed version for golang-1.25 issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 17 05:57:02 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
dc0d0edd by Salvatore Bonaccorso at 2026-08-17T06:56:31+02:00
Track fixed version for golang-1.25 issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5645,7 +5645,7 @@ CVE-2026-73251 [Built-in TLS certificate-chain verification with CA bundles]
 CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to two sumdb  ...)
 	- golang-1.27 <unfixed> (bug #1144340)
 	- golang-1.26 <unfixed> (bug #1144341)
-	- golang-1.25 <unfixed> (bug #1144342)
+	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
@@ -5657,7 +5657,7 @@ CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to two
 CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module content no ...)
 	- golang-1.27 <unfixed> (bug #1144340)
 	- golang-1.26 <unfixed> (bug #1144341)
-	- golang-1.25 <unfixed> (bug #1144342)
+	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
@@ -5669,7 +5669,7 @@ CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module cont
 CVE-2026-56859 (Previously, DecodeElement would reset the depth counter causing it to  ...)
 	- golang-1.27 <unfixed> (bug #1144340)
 	- golang-1.26 <unfixed> (bug #1144341)
-	- golang-1.25 <unfixed> (bug #1144342)
+	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
@@ -5681,7 +5681,7 @@ CVE-2026-56859 (Previously, DecodeElement would reset the depth counter causing
 CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it reads a  ...)
 	- golang-1.27 <unfixed> (bug #1144340)
 	- golang-1.26 <unfixed> (bug #1144341)
-	- golang-1.25 <unfixed> (bug #1144342)
+	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
@@ -5693,7 +5693,7 @@ CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it re
 CVE-2026-56860 (Previously, resolving relative paths containing parent directory ('..' ...)
 	- golang-1.27 <unfixed> (bug #1144340)
 	- golang-1.26 <unfixed> (bug #1144341)
-	- golang-1.25 <unfixed> (bug #1144342)
+	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
@@ -5705,7 +5705,7 @@ CVE-2026-56860 (Previously, resolving relative paths containing parent directory
 CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered as state- ...)
 	- golang-1.27 <unfixed> (bug #1144340)
 	- golang-1.26 <unfixed> (bug #1144341)
-	- golang-1.25 <unfixed> (bug #1144342)
+	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
@@ -5717,7 +5717,7 @@ CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered as
 CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' early, al ...)
 	- golang-1.27 <unfixed> (bug #1144340)
 	- golang-1.26 <unfixed> (bug #1144341)
-	- golang-1.25 <unfixed> (bug #1144342)
+	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
@@ -5729,7 +5729,7 @@ CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' ear
 CVE-2026-33818 (Enforce a recursion limit in Unmarshal to prevent stack exhaustion whe ...)
 	- golang-1.27 <unfixed> (bug #1144340)
 	- golang-1.26 <unfixed> (bug #1144341)
-	- golang-1.25 <unfixed> (bug #1144342)
+	- golang-1.25 1.25.13-1 (bug #1144342)
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc0d0edd8ed0b70ac6b3421d95c69b40506b1138

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc0d0edd8ed0b70ac6b3421d95c69b40506b1138
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/4b6c1880/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list