Skip to content

Conversation

@bu
Copy link
Owner

@bu bu commented Dec 30, 2025

Updated github.com/gin-gonic/gin from v1.6.3 to v1.11.0 to address:

  • CVE-2020-28483: IP spoofing vulnerability via X-Forwarded-For header
  • CVE-2023-26125: Improper input validation in X-Forwarded-Prefix header

Also updated dependencies to fix:

  • CVE-2024-45338: DoS vulnerability in golang.org/x/net/html (now v0.42.0)
  • CVE-2024-45337: Auth bypass in golang.org/x/crypto/ssh (now v0.40.0)

All tests pass successfully after the upgrade.

Updated github.com/gin-gonic/gin from v1.6.3 to v1.11.0 to address:
- CVE-2020-28483: IP spoofing vulnerability via X-Forwarded-For header
- CVE-2023-26125: Improper input validation in X-Forwarded-Prefix header

Also updated dependencies to fix:
- CVE-2024-45338: DoS vulnerability in golang.org/x/net/html (now v0.42.0)
- CVE-2024-45337: Auth bypass in golang.org/x/crypto/ssh (now v0.40.0)

All tests pass successfully after the upgrade.
@bu bu merged commit 72431e5 into main Dec 30, 2025
1 check passed
@bu bu deleted the claude/fix-fiber-cve-Yfm8C branch December 30, 2025 08:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants