Skip to content

fix(deps): update golang.org/x/text to v0.41.0 to resolve CVE-2026-56851 - #189

Merged
rickymoorhouse merged 1 commit into
mainfrom
fix_CVE-2026-56851
Oct 9, 2026
Merged

rickymoorhouse merged 1 commit into
mainfrom
fix_CVE-2026-56851

Conversation

@nikhitha-Ibm

Copy link
Copy Markdown
Collaborator

Description

This PR resolves CVE-2026-56851 by upgrading golang.org/x/text from v0.34.0 (root module) / v0.31.0 (nets module) to v0.41.0.

Vulnerability Details

  • CVE ID: CVE-2026-56851
  • Severity: High (CVSS: 7.5)
  • Affected Component: golang.org/x/text (< 0.41.0)
  • Fixed Version: 0.41.0
  • Description: The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.
  • Affected Artifact: /app/trawler

Changes Summary

  • Upgraded golang.org/x/text to v0.41.0 in go.mod and nets/go.mod.
  • Updated transitive indirect dependencies (golang.org/x/net, golang.org/x/sys, golang.org/x/term) to compatible versions.
  • Preserved Go version at go 1.25.0 (toolchain go1.25.7).
  • Updated go.sum, go.work.sum, nets/go.sum, and nets/go.work.sum.



Signed-off-by: nikhitha-ibm <nikhithaeldhose2@ibm.com>

@priyankacw11 priyankacw11 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@rickymoorhouse rickymoorhouse left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lgtm

@rickymoorhouse
rickymoorhouse merged commit b800904 into main Oct 9, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants