Skip to content

[Security] Update Go to 1.26.3 to fix CVEs#2928

Merged
Saipriya-1144 merged 1 commit into
mainfrom
security/fix-go-cves-1.26.3
May 22, 2026
Merged

[Security] Update Go to 1.26.3 to fix CVEs#2928
Saipriya-1144 merged 1 commit into
mainfrom
security/fix-go-cves-1.26.3

Conversation

@Shi1810
Copy link
Copy Markdown
Collaborator

@Shi1810 Shi1810 commented May 21, 2026

Summary

Updates Go stdlib from 1.26.2 to 1.26.3 across all runtime Dockerfiles and go.mod files to address high-severity CVEs in the Go standard library.

CVEs Fixed

Related

Files Changed

  • 20 Dockerfiles (Python, Node, PHP, .NET runtime images)
  • 6 go.mod files (startupscriptgenerator modules)
  • 1 test script (testStartupScriptGenerators.sh)
  • 1 GitHub workflow (unit-tests.yaml)

Testing

  • Buddy validation (pipeline 364425)
  • OryxTests (pipeline 368278)

@Shi1810 Shi1810 requested a review from a team as a code owner May 21, 2026 10:35
…14/33811

Updates Go stdlib from 1.26.2 to 1.26.3 across all runtime Dockerfiles and go.mod files to address high-severity CVEs in the Go standard library.

Fixes:
- CVE-2026-42499
- CVE-2026-39836
- CVE-2026-39820
- CVE-2026-33814
- CVE-2026-33811

ICM 801686913
@Shi1810 Shi1810 force-pushed the security/fix-go-cves-1.26.3 branch from 166c3aa to 8ea508c Compare May 21, 2026 10:43
@Shi1810 Shi1810 changed the title [Security] Update Go to 1.26.3 - fixes CVE-2026-42499/39836/39820/33814/33811 [Security] Update Go to 1.26.3 to fix CVEs May 21, 2026
@Saipriya-1144 Saipriya-1144 merged commit a6dd7e2 into main May 22, 2026
9 checks passed
@Saipriya-1144 Saipriya-1144 deleted the security/fix-go-cves-1.26.3 branch May 22, 2026 07:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants