Tuleap Community Edition development and releases are no longer public. You have until September 30th to download packages and sources in Tuleap project. You can contact the team if you need further assistance.

    •  
      request #46730 Go: temporarily ignore CVE-2025-61730 and CVE-2025-61726
    Infos
    #46730
    Kevin Traini (ktraini)
    2026-01-29 11:19
    2026-01-29 10:29
    48486
    Details
    Go: temporarily ignore CVE-2025-61730 and CVE-2025-61726

    There is no security impact for Tuleap.

    • TLS handshake is not handled by go.
    • The only URL we parse is builded by us.

    We can temporarily ignore this and upgrade to a fixed Go version later.

    Dependencies
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Kevin Traini (ktraini)
    Closed
    2026-01-29
    Attachments
    Empty
    References
    Referenced by request #46730

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2026-01-29 10:49

    TLS handshake is not handled by go.

    We have the case for Smokescreen and most likely our Vault plugin. I however agree we can delay it, it has very limited impact in our situation. To quote the advisory: "This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake."