renovate-bot opened a new pull request, #266:
URL: https://github.com/apache/superset-kubernetes-operator/pull/266

   This PR contains the following updates:
   
   | Package | Type | Update | Change |
   |---|---|---|---|
   | [go](https://go.dev/) ([source](https://redirect.github.com/golang/go)) | 
toolchain | patch | `1.26.5` → `1.26.6` |
   
   ---
   
   ### Invoking failure to reject ASCII-only Punycode-encoded labels in 
golang.org/x/net/idna
   [CVE-2026-39821](https://nvd.nist.gov/vuln/detail/CVE-2026-39821) / 
[GO-2026-5026](https://pkg.go.dev/vuln/GO-2026-5026)
   
   <details>
   <summary>More information</summary>
   
   #### Details
   The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded 
labels that decode to an ASCII-only label. For example, 
ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather 
than an error.
   
   This behavior can lead to privilege escalation in programs using the idna 
package. For example, a program which performs privilege checks on the ASCII 
hostname may reject "example.com" but permit "xn--example-.com". If that 
program subsequently converts the ASCII hostname to Unicode, it will 
inadvertently permits access to the Unicode name "example.com".
   
   #### Severity
   Unknown
   
   #### References
   - [https://go.dev/cl/767220](https://go.dev/cl/767220)
   - [https://go.dev/issue/78760](https://go.dev/issue/78760)
   - 
[https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8](https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8)
   - 
[https://groups.google.com/g/golang-announce/c/94pEornpRlI](https://groups.google.com/g/golang-announce/c/94pEornpRlI)
   
   This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-5026) 
and the [Go Vulnerability Database](https://redirect.github.com/golang/vulndb) 
([CC-BY 4.0](https://redirect.github.com/golang/vulndb#license)).
   </details>
   
   ---
   
   ### Parsing an invalid SVCB or HTTPS RR can panic in 
golang.org/x/net/dns/dnsmessage
   [CVE-2026-46600](https://nvd.nist.gov/vuln/detail/CVE-2026-46600) / 
[GO-2026-5942](https://pkg.go.dev/vuln/GO-2026-5942)
   
   <details>
   <summary>More information</summary>
   
   #### Details
   Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter 
value overflows the message buffer.
   
   #### Severity
   Unknown
   
   #### References
   - [https://go.dev/cl/786345](https://go.dev/cl/786345)
   - [https://go.dev/issue/79795](https://go.dev/issue/79795)
   - 
[https://groups.google.com/g/golang-announce/c/94pEornpRlI](https://groups.google.com/g/golang-announce/c/94pEornpRlI)
   
   This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-5942) 
and the [Go Vulnerability Database](https://redirect.github.com/golang/vulndb) 
([CC-BY 4.0](https://redirect.github.com/golang/vulndb#license)).
   </details>
   
   ---
   
   ### Enforce maximum recursion depth in encoding/asn1
   [CVE-2026-33818](https://nvd.nist.gov/vuln/detail/CVE-2026-33818) / 
[GO-2026-5972](https://pkg.go.dev/vuln/GO-2026-5972)
   
   <details>
   <summary>More information</summary>
   
   #### Details
   Enforce a recursion limit in Unmarshal to prevent stack exhaustion when 
parsing deeply-nested, recursive structures.
   
   #### Severity
   Unknown
   
   #### References
   - [https://go.dev/issue/80405](https://go.dev/issue/80405)
   - 
[https://groups.google.com/g/golang-announce/c/94pEornpRlI](https://groups.google.com/g/golang-announce/c/94pEornpRlI)
   - [https://go.dev/cl/814980](https://go.dev/cl/814980)
   
   This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-5972) 
and the [Go Vulnerability Database](https://redirect.github.com/golang/vulndb) 
([CC-BY 4.0](https://redirect.github.com/golang/vulndb#license)).
   </details>
   
   ---
   
   ### Add recursion depth guard during decode in encoding/xml
   [CVE-2026-56859](https://nvd.nist.gov/vuln/detail/CVE-2026-56859) / 
[GO-2026-6088](https://pkg.go.dev/vuln/GO-2026-6088)
   
   <details>
   <summary>More information</summary>
   
   #### Details
   Previously, DecodeElement would reset the depth counter causing it to never 
fire; this could lead to stack exhaustion.
   
   #### Severity
   Unknown
   
   #### References
   - [https://go.dev/issue/80481](https://go.dev/issue/80481)
   - [https://go.dev/cl/803320](https://go.dev/cl/803320)
   - 
[https://groups.google.com/g/golang-announce/c/94pEornpRlI](https://groups.google.com/g/golang-announce/c/94pEornpRlI)
   
   This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6088) 
and the [Go Vulnerability Database](https://redirect.github.com/golang/vulndb) 
([CC-BY 4.0](https://redirect.github.com/golang/vulndb#license)).
   </details>
   
   ---
   
   ### Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
   [CVE-2026-56853](https://nvd.nist.gov/vuln/detail/CVE-2026-56853) / 
[GO-2026-6089](https://pkg.go.dev/vuln/GO-2026-6089)
   
   <details>
   <summary>More information</summary>
   
   #### Details
   When a server is configured to support unencrypted HTTP/2, it reads a few 
bytes from each new connection to see if they contain the HTTP/2 client 
preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
   
   #### Severity
   Unknown
   
   #### References
   - [https://go.dev/issue/80205](https://go.dev/issue/80205)
   - [https://go.dev/cl/795540](https://go.dev/cl/795540)
   - 
[https://groups.google.com/g/golang-announce/c/94pEornpRlI](https://groups.google.com/g/golang-announce/c/94pEornpRlI)
   
   This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6089) 
and the [Go Vulnerability Database](https://redirect.github.com/golang/vulndb) 
([CC-BY 4.0](https://redirect.github.com/golang/vulndb#license)).
   </details>
   
   ---
   
   ### Limit handshake messages we are willing to accept post-handshake in 
crypto/tls
   [CVE-2026-56862](https://nvd.nist.gov/vuln/detail/CVE-2026-56862) / 
[GO-2026-6090](https://pkg.go.dev/vuln/GO-2026-6090)
   
   <details>
   <summary>More information</summary>
   
   #### Details
   Handshake messages, such as KeyUpdate, are always considered as 
state-advancing, regardless of whether a handshake has been completed or not. 
As a result, a malicious client can keep sending KeyUpdate messages to force 
the server to keep performing key derivation operations indefinitely.
   
   #### Severity
   Unknown
   
   #### References
   - [https://go.dev/issue/80528](https://go.dev/issue/80528)
   - [https://go.dev/cl/804261](https://go.dev/cl/804261)
   - 
[https://groups.google.com/g/golang-announce/c/94pEornpRlI](https://groups.google.com/g/golang-announce/c/94pEornpRlI)
   
   This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6090) 
and the [Go Vulnerability Database](https://redirect.github.com/golang/vulndb) 
([CC-BY 4.0](https://redirect.github.com/golang/vulndb#license)).
   </details>
   
   ---
   
   ### Fix Javascript regexp context tracking in html/template
   [CVE-2026-56858](https://nvd.nist.gov/vuln/detail/CVE-2026-56858) / 
[GO-2026-6091](https://pkg.go.dev/vuln/GO-2026-6091)
   
   <details>
   <summary>More information</summary>
   
   #### Details
   Previously, pathological inputs could close an unescaped '/' early, allowing 
for attack-controlled data to inject arbitrary content, potentially leading to 
XSS.
   
   #### Severity
   Unknown
   
   #### References
   - [https://go.dev/issue/80435](https://go.dev/issue/80435)
   - [https://go.dev/cl/807100](https://go.dev/cl/807100)
   - 
[https://groups.google.com/g/golang-announce/c/94pEornpRlI](https://groups.google.com/g/golang-announce/c/94pEornpRlI)
   
   This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6091) 
and the [Go Vulnerability Database](https://redirect.github.com/golang/vulndb) 
([CC-BY 4.0](https://redirect.github.com/golang/vulndb#license)).
   </details>
   
   ---
   
   ### Avoid quadratic complexity in resolvePath in net/url
   [CVE-2026-56860](https://nvd.nist.gov/vuln/detail/CVE-2026-56860) / 
[GO-2026-6218](https://pkg.go.dev/vuln/GO-2026-6218)
   
   <details>
   <summary>More information</summary>
   
   #### Details
   Previously, resolving relative paths containing parent directory ('..') 
segments performed string conversions and buffer rewrites on each step, 
resulting in quadratic time complexity and high memory allocation overhead.
   
   Now, path resolution operates on a byte buffer using index-based 
backtracking for '..' segments, eliminating the quadratic time complexity and 
significantly reducing memory allocations.
   
   #### Severity
   Unknown
   
   #### References
   - [https://go.dev/cl/803681](https://go.dev/cl/803681)
   - [https://go.dev/issue/80494](https://go.dev/issue/80494)
   - 
[https://groups.google.com/g/golang-announce/c/94pEornpRlI](https://groups.google.com/g/golang-announce/c/94pEornpRlI)
   
   This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-6218) 
and the [Go Vulnerability Database](https://redirect.github.com/golang/vulndb) 
([CC-BY 4.0](https://redirect.github.com/golang/vulndb#license)).
   </details>
   
   ---
   
   ### Release Notes
   
   <details>
   <summary>golang/go (go)</summary>
   
   ### 
[`v1.26.6`](https://redirect.github.com/golang/go/compare/go1.26.5...go1.26.6)
   
   </details>
   
   ---
   
   ### Configuration
   
   📅 **Schedule**: (UTC)
   
   - Branch creation
     - At any time (no schedule defined)
   - Automerge
     - At any time (no schedule defined)
   
   🚦 **Automerge**: Disabled by config. Please merge this manually once you are 
satisfied.
   
   ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry 
checkbox.
   
   🔕 **Ignore**: Close this PR and you won't be reminded about this update 
again.
   
   ---
   
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this 
box
   
   ---
   
   This PR was generated by [Mend Renovate](https://mend.io/renovate/). View 
the [repository job 
log](https://developer.mend.io/github/apache/superset-kubernetes-operator).
   
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjQuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsic2VjdXJpdHkiXX0=-->
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to