Skip to content

fix(deps): bump golang.org/x/text to v0.39.0 for CVE-2026-56852 - #385

Open
dbkreling wants to merge 1 commit into
openshift:mainfrom
dbkreling:fix/CVE-2026-56852
Open

fix(deps): bump golang.org/x/text to v0.39.0 for CVE-2026-56852#385
dbkreling wants to merge 1 commit into
openshift:mainfrom
dbkreling:fix/CVE-2026-56852

Conversation

@dbkreling

@dbkreling dbkreling commented Sep 2, 2026

Copy link
Copy Markdown

Summary

Bumps golang.org/x/text from v0.37.0 to v0.39.0 to resolve CVE-2026-56852.

CVE: CVE-2026-56852
Vulnerable range: < v0.39.0
Fixed in: v0.39.0
Jira ticket: KATA-5824

A norm.Iter in golang.org/x/text can enter an infinite loop when handling input containing invalid UTF-8 bytes.


This PR was created by the kata-bug-triage skill and supervised by Daniel Kreling.

Signed-off-by: Daniel Kreling <dkreling@redhat.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 2, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Team

Run ID: e2d371f2-d945-47d4-a7fa-519755c61c9e


Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant