Skip to content
This repository was archived by the owner on Jun 5, 2026. It is now read-only.

fix(security/unknown): update module golang.org/x/oauth2 to v0.27.0 [security]#299

Closed
renovate-sh-app[bot] wants to merge 1 commit into
mainfrom
renovate/go-golang.org-x-oauth2-vulnerability
Closed

fix(security/unknown): update module golang.org/x/oauth2 to v0.27.0 [security]#299
renovate-sh-app[bot] wants to merge 1 commit into
mainfrom
renovate/go-golang.org-x-oauth2-vulnerability

Conversation

@renovate-sh-app
Copy link
Copy Markdown
Contributor

@renovate-sh-app renovate-sh-app Bot commented Nov 27, 2025

This PR contains the following updates:

Package Change Age Confidence
golang.org/x/oauth2 v0.11.0v0.27.0 age confidence

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

CVE-2025-22868 / GHSA-6v2p-p543-phr9

More information

Details

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

CVE-2025-22868 / GHSA-6v2p-p543-phr9 / GO-2025-3488

More information

Details

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Unexpected memory consumption during token parsing in golang.org/x/oauth2

CVE-2025-22868 / GHSA-6v2p-p543-phr9 / GO-2025-3488

More information

Details

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

Need help?

You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.

@renovate-sh-app
Copy link
Copy Markdown
Contributor Author

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.21 -> 1.23.0
cloud.google.com/go/compute/metadata v0.2.3 -> v0.3.0

@renovate-sh-app renovate-sh-app Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 7 times, most recently from 90367d7 to d89eafc Compare November 28, 2025 06:35
@renovate-sh-app
Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.21 -> 1.23.0
cloud.google.com/go/compute/metadata v0.2.3 -> v0.3.0

@renovate-sh-app renovate-sh-app Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from d89eafc to ff1a42e Compare February 9, 2026 17:13
@renovate-sh-app renovate-sh-app Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from ff1a42e to a4a4a19 Compare March 19, 2026 16:04
@renovate-sh-app renovate-sh-app Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from a4a4a19 to a398b47 Compare May 8, 2026 16:03
@renovate-sh-app renovate-sh-app Bot changed the title chore(deps): update module golang.org/x/oauth2 to v0.27.0 [security] chore(deps): update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosed May 14, 2026
@renovate-sh-app renovate-sh-app Bot closed this May 14, 2026
@renovate-sh-app renovate-sh-app Bot deleted the renovate/go-golang.org-x-oauth2-vulnerability branch May 14, 2026 10:06
@renovate-sh-app renovate-sh-app Bot changed the title chore(deps): update module golang.org/x/oauth2 to v0.27.0 [security] - autoclosed fix(security/unknown): update module golang.org/x/oauth2 to v0.27.0 [security] May 15, 2026
@renovate-sh-app renovate-sh-app Bot reopened this May 15, 2026
@renovate-sh-app renovate-sh-app Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 2 times, most recently from a398b47 to 1dcb18a Compare May 15, 2026 16:07
…security]

| datasource | package             | from    | to      |
| ---------- | ------------------- | ------- | ------- |
| go         | golang.org/x/oauth2 | v0.11.0 | v0.27.0 |


Signed-off-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
@renovate-sh-app renovate-sh-app Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 1dcb18a to 00f662c Compare May 16, 2026 04:04
@renovate-sh-app
Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: go.sum
Command failed: go get -t ./...
go: golang.org/x/oauth2@v0.27.0: verifying go.mod: golang.org/x/oauth2@v0.27.0/go.mod: reading https://grafana-enterprise-cicd:xxxxx@buf.build/gen/go/sumdb/sum.golang.org/supported: 503 Service Unavailable
	server response: upstream connect error or disconnect/reset before headers. retried and the latest reset reason: connection timeout

@phlope phlope closed this May 20, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant