Skip to content

Update module golang.org/x/net to v0.51.0 [SECURITY]#2047

Merged
pulumi-renovate[bot] merged 1 commit intomainfrom
renovate/security
Feb 28, 2026
Merged

Update module golang.org/x/net to v0.51.0 [SECURITY]#2047
pulumi-renovate[bot] merged 1 commit intomainfrom
renovate/security

Conversation

@pulumi-renovate
Copy link
Contributor

This PR contains the following updates:

Package Type Update Change
golang.org/x/net indirect minor v0.50.0 -> v0.51.0

Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net

CVE-2026-27141 / GO-2026-4559

More information

Details

Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - Monday through Friday ( * * * * 1-5 ) (UTC).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@pulumi-renovate pulumi-renovate bot added dependencies Pull requests that update a dependency file impact/no-changelog-required This issue doesn't require a CHANGELOG update labels Feb 28, 2026
@pulumi-renovate pulumi-renovate bot requested a review from a team as a code owner February 28, 2026 13:42
@pulumi-renovate pulumi-renovate bot added impact/no-changelog-required This issue doesn't require a CHANGELOG update dependencies Pull requests that update a dependency file labels Feb 28, 2026
@pulumi-renovate pulumi-renovate bot enabled auto-merge (squash) February 28, 2026 13:42
@pulumi-renovate pulumi-renovate bot merged commit 87b609d into main Feb 28, 2026
20 checks passed
@pulumi-renovate pulumi-renovate bot deleted the renovate/security branch February 28, 2026 13:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file impact/no-changelog-required This issue doesn't require a CHANGELOG update

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants