Skip to content

fix(deps): update module golang.org/x/oauth2 to v0.27.0 [security]#921

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-golang.org-x-oauth2-vulnerability
Open

fix(deps): update module golang.org/x/oauth2 to v0.27.0 [security]#921
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-golang.org-x-oauth2-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Jul 18, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
golang.org/x/oauth2 v0.26.0v0.27.0 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

CVE-2025-22868 / GHSA-6v2p-p543-phr9

More information

Details

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot requested a review from a team as a code owner July 18, 2025 23:04
@codecov

codecov Bot commented Jul 18, 2025

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 64.52%. Comparing base (a714354) to head (ed9785b).

Additional details and impacted files
@@             Coverage Diff             @@
##             main     #921       +/-   ##
===========================================
+ Coverage   28.17%   64.52%   +36.34%     
===========================================
  Files         172      172               
  Lines       21718    21718               
===========================================
+ Hits         6119    14013     +7894     
+ Misses      15467     7081     -8386     
- Partials      132      624      +492     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 68fb402 to 2902157 Compare August 7, 2025 15:42
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 2902157 to 288e4ec Compare August 7, 2025 16:24
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 288e4ec to 95d7c9a Compare August 13, 2025 16:26
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 95d7c9a to f2e96f0 Compare September 25, 2025 15:48
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from f2e96f0 to de79703 Compare September 26, 2025 20:39
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from de79703 to e179f1b Compare September 26, 2025 20:44
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from e179f1b to a9884e2 Compare September 26, 2025 20:47
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from a9884e2 to d7c5903 Compare September 26, 2025 20:58
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from d7c5903 to 9588c8f Compare September 29, 2025 19:29
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 9945104 to aae12ca Compare October 4, 2025 00:18
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from aae12ca to d47911e Compare October 8, 2025 16:55
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from d47911e to 3e996b4 Compare October 8, 2025 20:36
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 3e996b4 to 2c009c1 Compare October 13, 2025 23:05
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 2c009c1 to 37b028a Compare October 20, 2025 18:29
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 37b028a to 07b0897 Compare October 20, 2025 21:01
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 07b0897 to c3922b7 Compare October 27, 2025 21:31
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from c3922b7 to b7ad1b3 Compare October 30, 2025 00:09
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from b7ad1b3 to 12049e8 Compare October 30, 2025 20:48
@renovate renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 12049e8 to 591e245 Compare November 3, 2025 19:16
@apiiro

apiiro Bot commented May 20, 2026

Copy link
Copy Markdown

Remediation actions:
⚠️ Heads up: Starting June 15, this SCA policy will be enforced as a hard gate. Please address these findings before merging

Workflows: "WORKFLOW-42 · SCA PR Comments for all Orgs"
Policies: "SCA Policy for Hard Gates"

⚠️ Apiiro found 1 resolved risk - 1 high ⚠️

Risks identified in /go.mod - 🔴 1 high Total detected risks 1, Displayed (deduplicated, showing only the highest severity per package): 1
🔴 1 high - golang.org/x/oauth2 · max CVSS 7.5
  • New SCA Policy for Hard Gates in dependency golang.org/x/oauth2
  • Dependency: golang.org/x/oauth2 : v0.26.0
  • Type: Direct
  • Insights: No version 1, Has vulnerabilities, Used in code, Public repository
  • Max CVSS Score: 7.5
  • Total Vulnerabilities 1(1 High):
ID Vulnerability CVSS Exploit maturity EPSS Fix version
CVE-2025-22868 golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability 7.5 No exploit maturity data Score: 0.00125
Percentile 31.1%
0.27.0

Remediation suggestions
Upgrade to golang.org/x/oauth2 v0.36.0:
1. Go to go.mod
2. Replace vulnerable version v0.26.0 with fix version v0.36.0
Upgrade to golang.org/x/oauth2 v0.27.0:
1. Go to go.mod
2. Replace vulnerable version v0.26.0 with fix version v0.27.0

Repository: terraform-provider-equinix
Applications: ORG - EQUINIX,PROJ: PUBLIC-OPENSOURCE (Auto)

View in Apiiro

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants