Skip to content

fix(deps): update module golang.org/x/oauth2 to v0.27.0 [security] - #1857

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-golang.org-x-oauth2-vulnerability
Open

fix(deps): update module golang.org/x/oauth2 to v0.27.0 [security]#1857
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-golang.org-x-oauth2-vulnerability

Conversation

@renovate

@renovaterenovateBot commented Jul 18, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
golang.org/x/oauth2v0.3.0v0.27.0ageconfidence

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

CVE-2025-22868 / GHSA-6v2p-p543-phr9

More information

Details

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate

renovateBot commented Jul 18, 2025

Copy link
Copy Markdown
ContributorAuthor

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated
  • The go directive was updated for compatibility reasons

Details:

PackageChange
go1.18 -> 1.23.0
cloud.google.com/go/compute/metadatav0.2.1 -> v0.3.0

@renovaterenovateBot changed the title fix(deps): update module golang.org/x/oauth2 to v0.27.0 [security]fix(deps): update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosedJul 20, 2025
@renovaterenovateBot closed this Jul 20, 2025
@renovate
renovateBot deleted the renovate/go-golang.org-x-oauth2-vulnerability branch July 20, 2025 17:22
@renovaterenovateBot changed the title fix(deps): update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosedfix(deps): update module golang.org/x/oauth2 to v0.27.0 [security]Jul 20, 2025
@renovaterenovateBot reopened this Jul 20, 2025
@renovate
renovateBotforce-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from acd3941 to e8130acCompareJuly 20, 2025 21:24
@renovate
renovateBotforce-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from e8130ac to 8cc2674CompareAugust 10, 2025 14:41
@renovate
renovateBotforce-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 8cc2674 to d2ad5b0CompareOctober 9, 2025 15:39
@renovate

renovateBot commented Dec 15, 2025

Copy link
Copy Markdown
ContributorAuthor

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated
  • The go directive was updated for compatibility reasons

Details:

PackageChange
go1.18 -> 1.23.0
cloud.google.com/go/compute/metadatav0.2.1 -> v0.3.0

@renovaterenovateBot changed the title fix(deps): update module golang.org/x/oauth2 to v0.27.0 [security]fix(deps): update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosedFeb 10, 2026
@renovaterenovateBot closed this Feb 10, 2026
@renovaterenovateBot changed the title fix(deps): update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosedfix(deps): update module golang.org/x/oauth2 to v0.27.0 [security]Feb 10, 2026
@renovaterenovateBot reopened this Feb 10, 2026
@renovate
renovateBotforce-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 2 times, most recently from d2ad5b0 to 432334cCompareFebruary 10, 2026 08:58
@renovaterenovateBot changed the title fix(deps): update module golang.org/x/oauth2 to v0.27.0 [security]fix(deps): update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosedMar 27, 2026
@renovaterenovateBot closed this Mar 27, 2026
@renovaterenovateBot changed the title fix(deps): update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosedfix(deps): update module golang.org/x/oauth2 to v0.27.0 [security]Mar 30, 2026
@renovaterenovateBot reopened this Mar 30, 2026
@renovate
renovateBotforce-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 2 times, most recently from 432334c to bb27bfcCompareMarch 30, 2026 18:17
@renovaterenovateBot changed the title fix(deps): update module golang.org/x/oauth2 to v0.27.0 [security]fix(deps): update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosedApr 27, 2026
@renovaterenovateBot closed this Apr 27, 2026
@renovaterenovateBot changed the title fix(deps): update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosedfix(deps): update module golang.org/x/oauth2 to v0.27.0 [security]Apr 27, 2026
@renovaterenovateBot reopened this Apr 27, 2026
@renovate
renovateBotforce-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 2 times, most recently from bb27bfc to ffc0c38CompareApril 27, 2026 23:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants