[PR #10436] Updated the version of golang/crypto and golang/net package to handle CVE-2025-22869, CVE-2025-22870, CVE-2025-22872 #13241

Closed
opened 2026-04-13 00:21:49 -05:00 by GiteaMirror · 0 comments
Owner

Original Pull Request: https://github.com/ollama/ollama/pull/10436

State: closed
Merged: Yes


This PR will update golang.org/x/crypto to version 0.36.0 to address the security vulnerability (CVE-2025-22869).
and also will update golang.org/x/net to version 0.38.0 to address the security vulnerabilities(CVE-2025-22870, CVE-2025-22872)

**Original Pull Request:** https://github.com/ollama/ollama/pull/10436 **State:** closed **Merged:** Yes --- This PR will update golang.org/x/crypto to version 0.36.0 to address the security vulnerability (CVE-2025-22869). and also will update golang.org/x/net to version 0.38.0 to address the security vulnerabilities(CVE-2025-22870, CVE-2025-22872)
GiteaMirror added the pull-request label 2026-04-13 00:21:49 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/ollama#13241