Skip to content

Follow up on quic-go update for GHSA-47m2-4cr7-mhcw #7379

@oaliska-mb

Description

@oaliska-mb

Issue Details

Hello,

I have created the now closed issue about the critical quic-go vulnerability (GHSA-47m2-4cr7-mhcw ) and requested an update to a safer quic-go version. I have seen the update commit to the v0.57 in master branch but the latest version of the Caddy still uses an unsafe version of the quic-go library.

I was wondering if is there any release date for publishing a new version that uses a safer quic-go version.

Kind Regards.

Ömer Faruk Alışkan on behalf of MBTS
Provider Information

Assistance Disclosure

No response

If AI was used, describe the extent to which it was used.

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions