Skip to content

chore(deps): Bump Go >= 1.24.12 to fix CVE-2025-61726#6219

Open
patelchaitany wants to merge 1 commit intofeast-dev:masterfrom
patelchaitany:fix/CVE-2025-61726-net-url
Open

chore(deps): Bump Go >= 1.24.12 to fix CVE-2025-61726#6219
patelchaitany wants to merge 1 commit intofeast-dev:masterfrom
patelchaitany:fix/CVE-2025-61726-net-url

Conversation

@patelchaitany
Copy link
Copy Markdown
Contributor

@patelchaitany patelchaitany commented Apr 2, 2026

Fix CVE-2025-61726 (memory exhaustion in net/url query parameter parsing, CVSS 7.5) by bumping the Go toolchain from 1.22.9 to 1.24.12 in the feast-operator go.mod and Dockerfile.


Open with Devin

@patelchaitany patelchaitany requested a review from a team as a code owner April 2, 2026 08:14
@patelchaitany patelchaitany changed the title chore(deps): bump Go >= 1.24.12 to fix CVE-2025-61726 chore(deps): Bump Go >= 1.24.12 to fix CVE-2025-61726 Apr 2, 2026
devin-ai-integration[bot]

This comment was marked as resolved.

@patelchaitany patelchaitany force-pushed the fix/CVE-2025-61726-net-url branch from 6cfae36 to dc9bd4b Compare April 2, 2026 10:00
Copy link
Copy Markdown
Collaborator

@shuchu shuchu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lgtm

@ntkathole ntkathole force-pushed the fix/CVE-2025-61726-net-url branch from dc9bd4b to 9ff5286 Compare April 2, 2026 12:35
devin-ai-integration[bot]

This comment was marked as resolved.

@patelchaitany patelchaitany force-pushed the fix/CVE-2025-61726-net-url branch 2 times, most recently from 46a5808 to 8a608ed Compare April 3, 2026 11:07
Bump the Go toolchain from 1.22.9 to 1.24.12 in the feast-operator
go.mod and Dockerfile to fix CVE-2025-61726 (memory exhaustion in
net/url query parameter parsing, CVSS 7.5).

Signed-off-by: Chaitany patel <patelchaitany93@gmail.com>
Made-with: Cursor
@patelchaitany patelchaitany force-pushed the fix/CVE-2025-61726-net-url branch from 8a608ed to 7707612 Compare April 3, 2026 11:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants