Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Mar 21, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
github.com/golang-jwt/jwt/v5 v5.2.1 -> v5.2.2 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2025-30204

Summary

Function parse.ParseUnverified currently splits (via a call to strings.Split) its argument (which is untrusted data) on periods.

As a result, in the face of a malicious request whose Authorization header consists of Bearer followed by many period characters, a call to that function incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. Relevant weakness: CWE-405: Asymmetric Resource Consumption (Amplification)

Details

See parse.ParseUnverified

Impact

Excessive memory allocation


Release Notes

golang-jwt/jwt (github.com/golang-jwt/jwt/v5)

v5.2.2

Compare Source

What's Changed

New Contributors

Full Changelog: golang-jwt/jwt@v5.2.1...v5.2.2


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the security label Mar 21, 2025
@renovate renovate bot requested review from a team as code owners March 21, 2025 22:11
@renovate renovate bot requested review from GenPage and removed request for a team March 21, 2025 22:11
@renovate renovate bot enabled auto-merge (squash) March 21, 2025 22:11
@renovate renovate bot requested review from X-Guardian and nitrocode and removed request for a team March 21, 2025 22:11
@dosubot dosubot bot added the dependencies PRs that update a dependency file label Mar 21, 2025
@renovate renovate bot merged commit f6d97cd into main Mar 21, 2025
36 of 39 checks passed
@renovate renovate bot deleted the renovate/main-go-github.colasdn.workers.dev-golang-jwt-jwt-v5-vulnerability branch March 21, 2025 22:17
CaioAugustoo pushed a commit to CaioAugustoo/atlantis that referenced this pull request Mar 27, 2025
…rity] (main) (runatlantis#5437)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
joe1981al pushed a commit to joe1981al/atlantis that referenced this pull request Jun 20, 2025
…rity] (main) (runatlantis#5437)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Signed-off-by: Joseph McDonald <[email protected]>
dimisjim pushed a commit to dimisjim/atlantis that referenced this pull request Oct 29, 2025
…rity] (main) (runatlantis#5437)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Signed-off-by: dimisjim <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies PRs that update a dependency file security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant