Security Vulnerability Report
Severity: Medium
Tool: govulncheck
Findings:
-
GO-2026-4341 - Memory exhaustion in query parameter parsing in net/url
-
GO-2026-4340 - Handshake messages may be processed at the incorrect encryption level in crypto/tls
- Fixed in:
crypto/[email protected]
- Affected:
internal/server/server.go:61, internal/tools/builtin.go:299, internal/tools/builtin.go:890, internal/session/notifier.go:137
-
GO-2026-4337 - Unexpected session resumption in crypto/tls
Recommendation: Upgrade Go to version 1.25.7 or later.