Bump Go version to 1.25 to fix govulncheck failures (#115)
Go 1.25.8 includes fixes for the following CVEs that are failing the Two vulncheck build for vpc-tunnel:
- CVE-2026-25679: Incorrect parsing of IPv6 host literals in net/url
- CVE-2026-27139: FileInfo can escape from a Root in os
- CVE-2026-27142: URLs in meta content attribute actions not escaped in html/template
- CVE-2026-27138: Panic in name constraint checking in crypto/x509
- CVE-2026-27137: Incorrect enforcement of email constraints in crypto/x509
Go 1.24 has no backported patches for these vulnerabilities.
Co-authored-by: Aviral Khattar avirak@amazon.com
版权所有:中国计算机学会技术支持:开源发展技术委员会
京ICP备13000930号-9
京公网安备 11010802032778号
Amazon VPC CNI Plugins
VPC CNI plugins for Amazon ECS and Amazon EKS.
Security disclosures
If you think you’ve found a potential security issue, please do not post it in the Issues. Instead, please follow the instructions here or email AWS security directly.
License
This library is licensed under the Apache 2.0 License.