go-openapi / spec

openapi specification object model
Apache License 2.0
394 stars 100 forks source link

High vulnerability in golang.org/x/text #149

Closed niting3c closed 3 years ago

niting3c commented 3 years ago

golang.org/x/text which has a here vulnerability as reported here: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14040

Short-term and Long-term upgrade fix is available in v0.3.7

Impacted Items: spec loads jsonreference

This is not an exhaustive list , there may be more