Skip to content

Conversation

pryon-shigh
Copy link

This updates golang.org/x/oauth2 from v0.18.0 to v0.30.0.

This update addresses CVE-2025-22868 in the oauth2 package. The addressed vulnerability is related to memory consumption during the parsing of tokens.

see: https://www.cve.org/CVERecord?id=CVE-2025-22868

> go mod why golang.org/x/oauth2
# golang.org/x/oauth2
github.com/golang-migrate/migrate/v4/source/github
golang.org/x/oauth2

@pryon-shigh
Copy link
Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant