The GO-2025-3447 security vulnerability report advises updating to Go 1.22.12, the latest 1.22 version of the Go compiler.
This came up during e2e testing a forked CometBFT library that applied this security patch. The v0.38 version of CometBFT still uses Go v1.22 and the v0.14.x version of the cometbft-db-testing Docker image.