Skip to content

Conversation

Bump golang.org/x/net from v0.12.0 to v0.17.0 Related: * golang/go#63417 * https://www.cve.org/CVERecord?id=CVE-2023-44487
@stefanb stefanb changed the title Fix CVE-2023-39325 / CVE-2023-44487 Fix CVE-2023-39325 / CVE-2023-44487 HTTP/2 Rapid Reset Attack Oct 11, 2023
@stefanb stefanb changed the title Fix CVE-2023-39325 / CVE-2023-44487 HTTP/2 Rapid Reset Attack Prevent CVE-2023-39325 / CVE-2023-44487 HTTP/2 Rapid Reset Attack Oct 11, 2023
@aldas aldas merged commit 5780908 into labstack:master Oct 11, 2023
@stefanb stefanb deleted the fix-CVE-2023-39325 branch October 11, 2023 04:15
@stefanb
Copy link
Contributor Author

stefanb commented Oct 11, 2023

@aldas, it would probably make sense to tag a release, so that dependants can get the fix easier. But of course it all depends on the current state of the project (v4.11.1...master ).

@stefanb stefanb mentioned this pull request Oct 11, 2023
@aldas
Copy link
Contributor

aldas commented Oct 11, 2023

@stefanb , I'll do it in couple of hours.

@aldas aldas mentioned this pull request Oct 11, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants