Skip to content

Release new version built with Go >= 1.25.7 (CVE-2025-68121) #8

@gifi71

Description

@gifi71

Hi! The pre-built binaries in v0.2.1 are compiled with Go 1.25.4, which is affected by CVE-2025-68121 (unexpected TLS session resumption in crypto/tls).
The fix is available in Go 1.24.13, 1.25.7, and 1.26.0-rc.3.
Could you publish a new release built with a patched Go version?
Detected by Trivy scanning the binary as gobinary in a Docker image. Currently working around this with .trivyignore.

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions