Skip to content

Conversation

pryon-shigh
Copy link

This updates golang.org/x/oauth2 from v0.18.0 to v0.30.0.

This update addresses CVE-2025-22868 in the oauth2 package. The addressed vulnerability is related to memory consumption during the parsing of tokens.

see: https://www.cve.org/CVERecord?id=CVE-2025-22868

> go mod why golang.org/x/oauth2
# golang.org/x/oauth2
github.com/golang-migrate/migrate/v4/source/github
golang.org/x/oauth2

@pryon-shigh
Copy link
Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant