Skip to content

CVE-2025-68121: Critical vulnerability in Go #16402

@iamigui

Description

@iamigui

Expected Behaviour
We noticed that knative-serving v1.21.0 appears to be built with Go 1.24.0, and that GHSA-h355-32pf-p2xm (crypto/tls session resumption issue) — rated Critical severity — is fixed in:

Go 1.24.13
Go 1.25.7
Go 1.26.0-rc3

Could you please let us know when the next knative-serving release is expected?

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions