Vulnerability of dependency "github.com/gin-gonic/gin" #529

Closed
opened 2025-12-29 02:19:35 +01:00 by adam · 2 comments
Owner

Originally created by @Silence-worker-02 on GitHub (Jul 14, 2023).

Hello, we are a team researching the dependency management mechanism of Golang. During our analysis, we came across your project and noticed that it contains a vulnerability (CVE-2023-26125). In your project, the github.com/gin-gonic/gin package is being used at version github.com/gin-gonic/gin v1.1.1, but the patched version is v1.9.0. To fix the vulnerability, we recommend modifying the go.mod file to update the version to v1.9.0 or higher. Thank you for your attention to this matter.

Originally created by @Silence-worker-02 on GitHub (Jul 14, 2023). Hello, we are a team researching the dependency management mechanism of Golang. During our analysis, we came across your project and noticed that it contains a vulnerability (CVE-2023-26125). In your project, the github.com/gin-gonic/gin package is being used at version github.com/gin-gonic/gin v1.1.1, but the patched version is v1.9.0. To fix the vulnerability, we recommend modifying the go.mod file to update the version to v1.9.0 or higher. Thank you for your attention to this matter.
adam added the stalebug labels 2025-12-29 02:19:35 +01:00
adam closed this issue 2025-12-29 02:19:35 +01:00
Author
Owner

@dennwc commented on GitHub (Sep 29, 2023):

Was fixed in #815.

@dennwc commented on GitHub (Sep 29, 2023): Was fixed in #815.
Author
Owner

@github-actions[bot] commented on GitHub (Dec 29, 2023):

This issue is stale because it has been open for 90 days with no activity.

@github-actions[bot] commented on GitHub (Dec 29, 2023): This issue is stale because it has been open for 90 days with no activity.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/headscale#529