•  
      request #47720 Temporarily ignore CVE-2026-42505 / GO-2026-5856
    Infos
    #47720
    Marie Ange Garnier (marieange)
    2026-07-09 17:49
    2026-07-09 11:33
    49462
    Details
    Temporarily ignore CVE-2026-42505 / GO-2026-5856

    The issue has a limited impact in Tuleap context. The fact that ECH could be de-anonymized is less critical in server-to-server communication scenario. Others ways to achieve the same result are very likely to be present anyway.

    https://go.dev/issue/79282

    Dependencies
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Marie Ange Garnier (marieange)
    Closed
    2026-07-09
    Attachments
    Empty
    References
    Referenced by request #47720

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2026-07-09 17:49
    • Summary
      -Go 1.26.4 => 1.26.5  
      +Temporarily ignore CVE-2026-42505 / GO-2026-5856 
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    • Connected artifacts