Commit 573dfe6
fix(cve): CVE-2026-42505 - update Go stdlib to 1.25.12
- Update go directive from 1.25.11 to 1.25.12
- Fixes Encrypted Client Hello (ECH) privacy leak in crypto/tls
- crypto/tls in Go 1.25.11 exposes cleartext SNI when invoking ECH
Fixes: CVE-2026-42505 (GO-2026-5856)
Co-Assisted-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent 4d3bd3f commit 573dfe6
1 file changed
Lines changed: 1 addition & 1 deletion
0 commit comments