fix(deps): update module golang.org/x/net to v0.60.0 [security] (#39695)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [golang.org/x/net](https://pkg.go.dev/golang.org/x/net) | [`v0.59.0` →
`v0.60.0`](https://cs.opensource.google/go/x/net/+/refs/tags/v0.59.0...refs/tags/v0.60.0)
|
![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fnet/v0.60.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fnet/v0.59.0/v0.60.0?slim=true)
|

---

### HTTP/2 server memory exhaustion due to Trailer headers in net/http
[CVE-2026-78659](https://nvd.nist.gov/vuln/detail/CVE-2026-78659) /
[GO-2026-6603](https://pkg.go.dev/vuln/GO-2026-6603)

<details>
<summary>More information</summary>

#### Details
When "Trailer" headers are sent by a client, the HTTP server internally
uses the header values to populate the Request.Trailer map passed to the
server handler. Because Request.Trailer is a map, each entry incurs
memory overhead. For HTTP/2 servers, a malicious client can exploit this
by sending a "Trailer" header that declares a large number of fields,
causing the server to allocate a disproportionate amount of memory while
bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits.
This exploit is not applicable for HTTP/1 servers, which do not support
multiplexing a large number of requests over one TCP connection, and
whose Server.MaxHeaderBytes are calculated differently.

#### Severity
Unknown

#### References
- [https://go.dev/cl/847185](https://go.dev/cl/847185)
- [https://go.dev/cl/847314](https://go.dev/cl/847314)
- [https://go.dev/issue/81857](https://go.dev/issue/81857)
-
[https://groups.google.com/g/golang-announce/c/U2fTuyDJznI](https://groups.google.com/g/golang-announce/c/U2fTuyDJznI)
-
[https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs](https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs)

This data is provided by
[OSV](https://osv.dev/vulnerability/GO-2026-6603) and the [Go
Vulnerability Database](https://redirect.github.com/golang/vulndb)
([CC-BY 4.0](https://redirect.github.com/golang/vulndb#license)).
</details>

---

### HTTP/2 transport accepts malformed framing-related headers in
net/http
[CVE-2026-78660](https://nvd.nist.gov/vuln/detail/CVE-2026-78660) /
[GO-2026-6610](https://pkg.go.dev/vuln/GO-2026-6610)

<details>
<summary>More information</summary>

#### Details
Historically, we have been rather lax about malformed framing-related
headers in our HTTP/2 implementation, as they cannot interfere with
HTTP/2 framing. However, this makes it possible for our HTTP/2
implementation to forward responses containing such headers to an HTTP/1
client when acting as a reverse proxy. If the HTTP/1 client also does
not behave strictly enough, this can result in response smuggling.

#### Severity
Unknown

#### References
- [https://go.dev/cl/835145](https://go.dev/cl/835145)
- [https://go.dev/cl/836385](https://go.dev/cl/836385)
- [https://go.dev/issue/81115](https://go.dev/issue/81115)
-
[https://groups.google.com/g/golang-announce/c/U2fTuyDJznI](https://groups.google.com/g/golang-announce/c/U2fTuyDJznI)

This data is provided by
[OSV](https://osv.dev/vulnerability/GO-2026-6610) and the [Go
Vulnerability Database](https://redirect.github.com/golang/vulndb)
([CC-BY 4.0](https://redirect.github.com/golang/vulndb#license)).
</details>

---

### Excessive CPU consumption from repeated initial window changes in
net/http
[CVE-2026-78669](https://nvd.nist.gov/vuln/detail/CVE-2026-78669) /
[GO-2026-6611](https://pkg.go.dev/vuln/GO-2026-6611)

<details>
<summary>More information</summary>

#### Details
A malicious HTTP/2 peer can cause excessive CPU consumption in the
client or server by opening a large number of streams and then sending
many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE
values.

#### Severity
Unknown

#### References
- [https://go.dev/cl/847186](https://go.dev/cl/847186)
- [https://go.dev/cl/847308](https://go.dev/cl/847308)
- [https://go.dev/issue/81742](https://go.dev/issue/81742)
-
[https://groups.google.com/g/golang-announce/c/U2fTuyDJznI](https://groups.google.com/g/golang-announce/c/U2fTuyDJznI)
-
[https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs](https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs)

This data is provided by
[OSV](https://osv.dev/vulnerability/GO-2026-6611) and the [Go
Vulnerability Database](https://redirect.github.com/golang/vulndb)
([CC-BY 4.0](https://redirect.github.com/golang/vulndb#license)).
</details>

---

### Double flow control refund on HTTP/2 server streams in net/http
[CVE-2026-78663](https://nvd.nist.gov/vuln/detail/CVE-2026-78663) /
[GO-2026-6612](https://pkg.go.dev/vuln/GO-2026-6612)

<details>
<summary>More information</summary>

#### Details
The HTTP/2 server can refund connection-level flow control twice for the
same data: Once when a client resets a stream (refunding data for any
sent-but-unread portion of the stream), and again when a request handler
reads the buffered data. A malicious client can exploit this to bypass
the configured connection-level flow control limit
(MaxReceiveBufferPerConnection). Total buffered data is still limited by
the concurrent stream limit and stream-level flow control.

#### Severity
Unknown

#### References
- [https://go.dev/cl/847187](https://go.dev/cl/847187)
- [https://go.dev/cl/847310](https://go.dev/cl/847310)
- [https://go.dev/issue/81743](https://go.dev/issue/81743)
-
[https://groups.google.com/g/golang-announce/c/U2fTuyDJznI](https://groups.google.com/g/golang-announce/c/U2fTuyDJznI)
-
[https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs](https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs)

This data is provided by
[OSV](https://osv.dev/vulnerability/GO-2026-6612) and the [Go
Vulnerability Database](https://redirect.github.com/golang/vulndb)
([CC-BY 4.0](https://redirect.github.com/golang/vulndb#license)).
</details>

---

### HTTP/2 server crash due to HPACK encoder race in net/http
[CVE-2026-97032](https://nvd.nist.gov/vuln/detail/CVE-2026-97032) /
[GO-2026-6617](https://pkg.go.dev/vuln/GO-2026-6617)

<details>
<summary>More information</summary>

#### Details
HTTP/2 servers could end up crashing due to inadvertently modifying its
HPACK encoder concurrently. This happens because the server modifies the
HPACK encoder from two goroutines without synchronization: one uses the
encoder to encode a HEADERS frame as part of a response sent to a client
and the other modifies the encoder's table size when handling a SETTINGS
frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A
malicious client can repeatedly send a request while changing the header
table size to crash the server.

#### Severity
Unknown

#### References
- [https://go.dev/cl/847188](https://go.dev/cl/847188)
- [https://go.dev/cl/847313](https://go.dev/cl/847313)
- [https://go.dev/issue/81867](https://go.dev/issue/81867)
-
[https://groups.google.com/g/golang-announce/c/U2fTuyDJznI](https://groups.google.com/g/golang-announce/c/U2fTuyDJznI)
-
[https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs](https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs)

This data is provided by
[OSV](https://osv.dev/vulnerability/GO-2026-6617) and the [Go
Vulnerability Database](https://redirect.github.com/golang/vulndb)
([CC-BY 4.0](https://redirect.github.com/golang/vulndb#license)).
</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend Renovate
CLI](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMjEuNCIsInVwZGF0ZWRJblZlciI6IjQ0LjEyMS40IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->
This commit is contained in:
Giteabot authored and GitHub committed 2026-10-09 05:47:50 +02:00
1 parent 437ca2dc6f
commit 2f94380222
2 files changed
+3 -3

No files matched your search

+1 -1
View File
@@ -92,7 +92,7 @@ require (
golang.org/x/crypto v0.57.0
golang.org/x/image v0.46.0
golang.org/x/mod v0.41.0
golang.org/x/net v0.59.0
golang.org/x/net v0.60.0
golang.org/x/oauth2 v0.37.0
golang.org/x/sync v0.23.0
golang.org/x/sys v0.48.0
+2 -2
View File
@@ -630,8 +630,8 @@ golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwY
golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg=
golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c=
golang.org/x/net v0.7.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs=
golang.org/x/net v0.59.0 h1:5zfYln+w5XCxwrnMMJPufRgNoXEaGxl0wo5GqPXyues=
golang.org/x/net v0.59.0/go.mod h1:2DA/G1UfVbCpQPeWTmMPGY7Cs2PkBkwu743bVX5PIVg=
golang.org/x/net v0.60.0 h1:79p50tfZlm0J9YfoDsSi639qSXNGVwEzOPLCxM2FsYU=
golang.org/x/net v0.60.0/go.mod h1:2DA/G1UfVbCpQPeWTmMPGY7Cs2PkBkwu743bVX5PIVg=
golang.org/x/oauth2 v0.37.0 h1:JUlcxA8oAtauLfiH8FX2/FkAWHAdi0QtGCGc+hofE98=
golang.org/x/oauth2 v0.37.0/go.mod h1:IxwZNxUULJmpBFf9K/9NTMSIfZZuvuTy1gGxhigP/58=
golang.org/x/sync v0.0.0-20180314180146-1d60e4601c6f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=