•  
      request #46730 Go: temporarily ignore CVE-2025-61730 and CVE-2025-61726
    Infos
    #46730
    Kevin Traini (ktraini)
    2026-01-29 11:19
    2026-01-29 10:29
    48451
    Details
    Go: temporarily ignore CVE-2025-61730 and CVE-2025-61726

    There is no security impact for Tuleap.

    • TLS handshake is not handled by go.
    • The only URL we parse is builded by us.

    We can temporarily ignore this and upgrade to a fixed Go version later.

    Dependencies
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Kevin Traini (ktraini)
    Closed
    2026-01-29
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2026-01-29 10:49

    TLS handshake is not handled by go.

    We have the case for Smokescreen and most likely our Vault plugin. I however agree we can delay it, it has very limited impact in our situation. To quote the advisory: "This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake."