Skip to content

Fix CVE-2026-42504: bump Go toolchain to 1.26.4#5

Merged
sudarshanrampuria merged 1 commit into
masterfrom
fix/CVE-2026-42504-go-1.26.4
Jul 7, 2026
Merged

Fix CVE-2026-42504: bump Go toolchain to 1.26.4#5
sudarshanrampuria merged 1 commit into
masterfrom
fix/CVE-2026-42504-go-1.26.4

Conversation

@sudarshanrampuria

Copy link
Copy Markdown

No description provided.

CVE-2026-42504 is a DoS (CWE-407, quadratic complexity) in the Go
stdlib mime.WordDecoder.DecodeHeader, fixed in Go 1.26.4 / 1.25.11.
The v1.1.3 binaries were built with Go 1.26.3 and are flagged as
vulnerable. Bump GO_VERSION and go.mod to 1.26.4 and cut v1.1.4.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@sudarshanrampuria
sudarshanrampuria requested a review from a team as a code owner July 7, 2026 09:07
@sudarshanrampuria
sudarshanrampuria merged commit 229a406 into master Jul 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants