Skip to content
This repository was archived by the owner on Jan 22, 2026. It is now read-only.

deps: update module github.com/golang-jwt/jwt/v5 to v5.2.2 [SECURITY]#3702

Merged
msanft merged 1 commit intomainfrom
renovate/go-github.com-golang-jwt-jwt-v5-vulnerability
Mar 23, 2025
Merged

deps: update module github.com/golang-jwt/jwt/v5 to v5.2.2 [SECURITY]#3702
msanft merged 1 commit intomainfrom
renovate/go-github.com-golang-jwt-jwt-v5-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Mar 21, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
github.com/golang-jwt/jwt/v5 v5.2.1 -> v5.2.2 age adoption passing confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

GitHub Vulnerability Alerts

CVE-2025-30204

Summary

Function parse.ParseUnverified currently splits (via a call to strings.Split) its argument (which is untrusted data) on periods.

As a result, in the face of a malicious request whose Authorization header consists of Bearer followed by many period characters, a call to that function incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. Relevant weakness: CWE-405: Asymmetric Resource Consumption (Amplification)

Details

See parse.ParseUnverified

Impact

Excessive memory allocation


Release Notes

golang-jwt/jwt (github.com/golang-jwt/jwt/v5)

v5.2.2

Compare Source

What's Changed

New Contributors

Full Changelog: golang-jwt/jwt@v5.2.1...v5.2.2


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Mar 21, 2025
@netlify
Copy link
Copy Markdown

netlify Bot commented Mar 21, 2025

Deploy Preview for constellation-docs canceled.

Name Link
🔨 Latest commit ba78894
🔍 Latest deploy log https://app.netlify.com/sites/constellation-docs/deploys/67ddf21eff058800083ca6df

@msanft msanft merged commit f4840de into main Mar 23, 2025
9 of 10 checks passed
@msanft msanft deleted the renovate/go-github.com-golang-jwt-jwt-v5-vulnerability branch March 23, 2025 17:07
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant