Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump net package version to 0.33 to avoid vulnerability #18

Merged
merged 4 commits into from
Dec 19, 2024

Conversation

julieta-311
Copy link
Owner

Dependabot alerted that any version below v0.33.0 is vulnerable to the following issue

An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.

https://github.com/julieta-311/proglog/security/dependabot/13

Dependabot alerted that any version below v0.33.0 is vulnerable
to the following issue

```
An attacker can craft an input to the Parse functions that would
be processed non-linearly with respect to its length, resulting
in extremely slow parsing. This could cause a denial of service.
```
@julieta-311 julieta-311 merged commit 970eeaa into master Dec 19, 2024
4 checks passed
@julieta-311 julieta-311 deleted the dependabot-net-alert branch December 19, 2024 12:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant