Files
podman/vendor
Lokesh Mandvekar 5eed4f1ec7 Update golang.org/x/crypto to v0.53.0 for CVE-2026-39830 and CVE-2026-42508
CVE-2026-39830: Invoking client can cause server deadlock on
unexpected responses in golang.org/x/crypto/ssh

CVE-2026-42508: Revoked SignatureKey not correctly checked for
revocation in golang.org/x/crypto/ssh/knownhosts

Update golang.org/x/crypto from v0.50.0 to v0.53.0.

References:
- https://pkg.go.dev/vuln/GO-2026-5017
- https://pkg.go.dev/vuln/GO-2026-5021
- https://go.dev/issue/79564
- https://go.dev/issue/79568

Signed-off-by: Lokesh Mandvekar <lsm5@linux.com>
2026-06-23 11:06:08 -04:00
..
2026-06-09 17:13:35 -04:00