Skip to content

Update module golang.org/x/net to v0.55.0 - #6

Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/golang.org-x-net-0.x
Open

Update module golang.org/x/net to v0.55.0#6
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/golang.org-x-net-0.x

Update module golang.org/x/net to v0.55.0

58b505d
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Sep 9, 2026 in 5m 46s

Security Report

You have successfully remediated 12 vulnerabilities, but introduced 22 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2026-46595

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@⁠v/v0.51.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ golang.org/x/crypto-v0.51.0 (Vulnerable Library)

Critical 10.0 Transitive golang.org/x/crypto-v0.51.0 github.com/Go-git/go-git/v5-v5.11.0 Transitive v0.52.0 None
CVE-941441-362681

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> shelljs-0.8.5.tgz

     -> glob-7.2.3.tgz

       -> ❌ once-1.4.0.tgz (Vulnerable Library)

Critical 9.8 Transitive once-1.4.0.tgz core-2.4.0.tgz None
CVE-2026-42508

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@⁠v/v0.51.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ golang.org/x/crypto-v0.51.0 (Vulnerable Library)

Critical 9.1 Transitive golang.org/x/crypto-v0.51.0 github.com/Go-git/go-git/v5-v5.11.0 Transitive v0.52.0 None
CVE-2026-39834

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@⁠v/v0.51.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ golang.org/x/crypto-v0.51.0 (Vulnerable Library)

Critical 9.1 Transitive golang.org/x/crypto-v0.51.0 github.com/Go-git/go-git/v5-v5.11.0 Transitive v0.52.0 None
CVE-2026-39832

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@⁠v/v0.51.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ golang.org/x/crypto-v0.51.0 (Vulnerable Library)

Critical 9.1 Transitive golang.org/x/crypto-v0.51.0 github.com/Go-git/go-git/v5-v5.11.0 Transitive v0.52.0 None
CVE-2026-39831

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@⁠v/v0.51.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ golang.org/x/crypto-v0.51.0 (Vulnerable Library)

Critical 9.1 Transitive golang.org/x/crypto-v0.51.0 github.com/Go-git/go-git/v5-v5.11.0 Transitive v0.52.0 None
CVE-2026-44728

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> preset-env-7.24.7.tgz

     -> ❌ plugin-transform-modules-systemjs-7.24.7.tgz (Vulnerable Library)

High 8.2 Transitive plugin-transform-modules-systemjs-7.24.7.tgz core-2.4.0.tgz Transitive 7.29.4 None
CVE-2026-44973

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/github.com/go-git/go-billy/v5/@⁠v/v5.5.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ github.com/go-git/go-Billy/v5-v5.5.0 (Vulnerable Library)

High 8.1 Transitive github.com/go-git/go-Billy/v5-v5.5.0 github.com/Go-git/go-git/v5-v5.11.0 None
CVE-2026-46599

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/image/@⁠v/v0.12.0.mod

Dependency Hierarchy:

-> github.com/leaanthony/winicon-v1.0.0 (Root Library)

   -> ❌ golang.org/x/image-v0.12.0 (Vulnerable Library)

High 7.5 Transitive golang.org/x/image-v0.12.0 github.com/leaanthony/winicon-v1.0.0 Transitive golang.org/x/image - v0.41.0 None
CVE-2026-46599

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/image/@⁠v/v0.12.0.mod

Dependency Hierarchy:

-> github.com/tc-hib/winres-v0.2.1 (Root Library)

   -> ❌ golang.org/x/image-v0.12.0 (Vulnerable Library)

High 7.5 Transitive golang.org/x/image-v0.12.0 github.com/tc-hib/winres-v0.2.1 Transitive golang.org/x/image - v0.41.0 None
CVE-2026-46597

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@⁠v/v0.51.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ golang.org/x/crypto-v0.51.0 (Vulnerable Library)

High 7.5 Transitive golang.org/x/crypto-v0.51.0 github.com/Go-git/go-git/v5-v5.11.0 Transitive v0.52.0 None
CVE-2026-44740

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/github.com/go-git/go-billy/v5/@⁠v/v5.5.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ github.com/go-git/go-Billy/v5-v5.5.0 (Vulnerable Library)

Medium 6.5 Transitive github.com/go-git/go-Billy/v5-v5.5.0 github.com/Go-git/go-git/v5-v5.11.0 None
CVE-2026-39827

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@⁠v/v0.51.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ golang.org/x/crypto-v0.51.0 (Vulnerable Library)

Medium 6.5 Transitive golang.org/x/crypto-v0.51.0 github.com/Go-git/go-git/v5-v5.11.0 Transitive v0.52.0 None
CVE-2026-1229

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/github.com/cloudflare/circl/@⁠v/v1.3.7.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> github.com/ProtonMail/go-crypto-v0.0.0-20230828082145-3c4c8a2d2371

     -> ❌ github.com/Cloudflare/circl-v1.3.7 (Vulnerable Library)

Medium 6.5 Transitive github.com/Cloudflare/circl-v1.3.7 github.com/Go-git/go-git/v5-v5.11.0 None
CVE-2026-39828

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@⁠v/v0.51.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ golang.org/x/crypto-v0.51.0 (Vulnerable Library)

Medium 6.3 Transitive golang.org/x/crypto-v0.51.0 github.com/Go-git/go-git/v5-v5.11.0 Transitive v0.52.0 None
CVE-2025-27789

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> core-7.24.7.tgz

     -> ❌ helpers-7.24.7.tgz (Vulnerable Library)

Medium 6.2 Transitive helpers-7.24.7.tgz core-2.4.0.tgz Transitive 7.26.10 None
CVE-2025-27789

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> ❌ runtime-corejs3-7.24.7.tgz (Vulnerable Library)

Medium 6.2 Transitive runtime-corejs3-7.24.7.tgz core-2.4.0.tgz Transitive 7.26.10 None
CVE-2025-27789

Path to dependency file: /website/package.json

Path to vulnerable library: /website/package.json

Dependency Hierarchy:

-> core-2.4.0.tgz (Root Library)

   -> ❌ runtime-7.24.7.tgz (Vulnerable Library)

Medium 6.2 Transitive runtime-7.24.7.tgz core-2.4.0.tgz Transitive 7.26.10 None
CVE-2026-46598

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@⁠v/v0.51.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ golang.org/x/crypto-v0.51.0 (Vulnerable Library)

Medium 5.3 Transitive golang.org/x/crypto-v0.51.0 github.com/Go-git/go-git/v5-v5.11.0 Transitive v0.52.0 None
CVE-2026-39835

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@⁠v/v0.51.0.mod

Dependency Hierarchy:

-> github.com/Go-git/go-git/v5-v5.11.0 (Root Library)

   -> ❌ golang.org/x/crypto-v0.51.0 (Vulnerable Library)

Medium 5.3 Transitive golang.org/x/crypto-v0.51.0 github.com/Go-git/go-git/v5-v5.11.0 Transitive v0.52.0 None
CVE-2026-33809

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/image/@⁠v/v0.12.0.mod

Dependency Hierarchy:

-> github.com/leaanthony/winicon-v1.0.0 (Root Library)

   -> ❌ golang.org/x/image-v0.12.0 (Vulnerable Library)

Medium 5.3 Transitive golang.org/x/image-v0.12.0 github.com/leaanthony/winicon-v1.0.0 Transitive v0.38.0 None
CVE-2026-33809

Path to dependency file: /v2/go.mod

Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/image/@⁠v/v0.12.0.mod

Dependency Hierarchy:

-> github.com/tc-hib/winres-v0.2.1 (Root Library)

   -> ❌ golang.org/x/image-v0.12.0 (Vulnerable Library)

Medium 5.3 Transitive golang.org/x/image-v0.12.0 github.com/tc-hib/winres-v0.2.1 Transitive v0.38.0 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2026-39828 golang.org/x/crypto-v0.23.0
CVE-2025-22869 golang.org/x/crypto-v0.23.0
CVE-2026-39827 golang.org/x/crypto-v0.23.0
CVE-2026-39832 golang.org/x/crypto-v0.23.0
CVE-2026-42508 golang.org/x/crypto-v0.23.0
CVE-2025-47914 golang.org/x/crypto-v0.23.0
CVE-2026-25680 golang.org/x/net-v0.25.0
CVE-2024-45337 golang.org/x/crypto-v0.23.0
CVE-2026-46595 golang.org/x/crypto-v0.23.0
CVE-2026-39835 golang.org/x/crypto-v0.23.0
CVE-2025-58181 golang.org/x/crypto-v0.23.0
CVE-2025-47913 golang.org/x/crypto-v0.23.0

Base branch total remaining vulnerabilities: 132
Base branch commit: null


Total libraries scanned: 1224

Scan token: e9b2db48e49046a085706b21b6293ab3