Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-74928

Update to go 1.25.6 to resolve CVEs

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • 4.22
    • OLM
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • Rejected
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

          We are using OPM v1.62.0 and our scans are showing a handful of high/medium CVEs related to the go version being used. I understand that OPM currently only has access to go 1.25.3, however many of the fixes are resolved in 1.25.5/1.25.6.

      Version-Release number of selected component (if applicable):

          OPM v1.62.0

      Actual results:

      High   CVE-2025-61729 Fixed in go 1.25.5
      High   CVE-2025-61726 Fixed in go 1.25.6
      Medium CVE-2025-61727 Fixed in go 1.25.5
      Medium CVE-2025-61730 Fixed in go 1.25.6
      Medium CVE-2025-61728 Fixed in go 1.25.6

      Expected results:

      All critical/high/medium CVEs related to go are resolved    

              rh-ee-cchantse Catherine Chan-Tse
              thomasleahibm Thomas Leah
              None
              None
              bruno andrade bruno andrade
              None
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: