Skip to content

Fix possible fix(deps): 8 vulnerable dependencies in go.mod - #6

Open
begininvoke wants to merge 1 commit into
PurrNet:mainfrom
begininvoke:redgem/security-fix-d8188dfb
Open

Fix possible fix(deps): 8 vulnerable dependencies in go.mod#6
begininvoke wants to merge 1 commit into
PurrNet:mainfrom
begininvoke:redgem/security-fix-d8188dfb

Conversation

@begininvoke

@begininvoke begininvoke commented Sep 12, 2026

Copy link
Copy Markdown

This changes PurrLay/PurrLay.WebRtcGateway/go.mod to address something a scan flagged. It is around line 1.

The vulnerability (CVE‑2026‑27136) in golang.org/x/net v0.50.0 stems from its HTML parser, which can generate unexpected DOM trees when processing arbitrary HTML. If the application then renders this HTML even after attempting sanitization, an attacker can craft input that bypasses filters and execute XSS in users' browsers. The issue is resolved in version 0.55.0, making an upgrade essential to eliminate the risk.

Update vulnerable indirect dependencies golang.org/x/net and golang.org/x/crypto to patched versions (0.56.0 and 0.55.0 respectively).

For reference: rule CVE-2026-27136. Rated high.

Take or leave whichever parts are useful. If this is not the right approach, closing is fine.


Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant