Skip to content

[v25.2.x] Bump github.com/moby/spdystream to v0.5.1 (CVE-2026-35469)#1498

Open
twmb wants to merge 2 commits intorelease/v25.2.xfrom
tb/bump-spdystream-v25.2.x
Open

[v25.2.x] Bump github.com/moby/spdystream to v0.5.1 (CVE-2026-35469)#1498
twmb wants to merge 2 commits intorelease/v25.2.xfrom
tb/bump-spdystream-v25.2.x

Conversation

@twmb
Copy link
Copy Markdown
Contributor

@twmb twmb commented May 1, 2026

Summary

Backport of #1495 to release/v25.2.x.

Bumps github.com/moby/spdystream from v0.5.0 to v0.5.1 across all workspace modules to address Snyk finding.

Vulnerability

Allocation of Resources Without Limits or Throttling in github.com/moby/spdystream/spdy@0.5.0

References

🤖 Generated with Claude Code

Backport of #1495.

Allocation of Resources Without Limits or Throttling vulnerability in
github.com/moby/spdystream/spdy. Fixed in v0.5.1.

References:
- https://nvd.nist.gov/vuln/detail/CVE-2026-35469
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMMOBYSPDYSTREAMSPDY-16304822
- GHSA-pc3f-x583-g7j2

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
CI's go-licenses produced these line additions after the spdystream
bump. Applied per skill workflow (let CI fail once, apply diff, push).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant