Skip to content

Backport fix for GHSA-7h2j-956f-4vf2 to v1#101

Merged
juliangruber merged 1 commit intojuliangruber:v1from
vitolob:backport-ghsa-7h2j-956f-4vf2-v1
Apr 4, 2026
Merged

Backport fix for GHSA-7h2j-956f-4vf2 to v1#101
juliangruber merged 1 commit intojuliangruber:v1from
vitolob:backport-ghsa-7h2j-956f-4vf2-v1

Conversation

@vitolob
Copy link
Copy Markdown

@vitolob vitolob commented Apr 2, 2026

This PR proposes a minimal backport of the expansion-cap mitigation for GHSA-7h2j-956f-4vf2 / CVE-2026-25547 to the v1 maintenance line, similar to #100

Why:

  • v1.1.13 addresses a separate issue, but does not include the expansion-cap mitigation
  • this keeps the patch narrow and aligned with the existing v1 codebase

References:

Refs #99

@juliangruber juliangruber merged commit 0d7652e into juliangruber:v1 Apr 4, 2026
20 checks passed
juliangruber added a commit that referenced this pull request Apr 4, 2026
juliangruber added a commit that referenced this pull request Apr 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants