hashicorp / hashicorp/envconsul

CVE-2025-47913 & CVE-2026-34986

Open
#409 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
2.1k
Forks
194
PR merge metrics
No merged PRs in 30d

Description

The library `golang.org/x/crypto` version `0.40.0` was detected in envconsul and is vulnerable to `CVE-2025-47913`, which exists in versions `< 0.43.0`.

⁠The library `github.com/go-jose/go-jose/v4` version `4.1.1` was detected in envconsul and is vulnerable to `CVE-2026-34986`, which exists in versions `< 4.1.4`.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.