hashicorp / hashicorp/consul

Feature / Dependency Update

Open
#22,539 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
30.1k
Forks
4.6k
Avg merge
1d 18h
Merged PRs (30d)
39

Description

## Background
As per the recently disclosed [CVE-2025-52893](https://nvd.nist.gov/vuln/detail/CVE-2025-52893), the [mitchellh/mapstructure](https://github.com/mitchellh/mapstructure) package has been identified as vulnerable. Security scanners are flagging this as a transitive dependency, which is triggering findings in our pipelines.

## Proposal
There is a maintained fork of the package under [go-viper/mapstructure](https://github.com/go-viper/mapstructure) that has already addressed this vulnerability. If the Consul team is open to it, I’d be happy to submit a PR replacing the current dependency with the patched fork.

Please let me know if this approach aligns with your standards and direction. I'm happy to assist with implementation.

Contributor guide

Open the contributing guide

Research direction

No files or tests are identified in the issue. Start by locating the current mitchellh/mapstructure dependency in the Consul repository and compare the go-viper/mapstructure fork and its vulnerability fix. Done means the patched fork is adopted and dependency or security checks pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
infrastructure
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.