go-resty / resty

Simple HTTP and REST client library for Go
MIT License
9.68k stars 681 forks source link

CVE-2023-45286 #756

Closed jeromedoucet closed 6 months ago

jeromedoucet commented 7 months ago

Hello !

It seems there is currently a CVE affecting at least the v2.10.0 version of resty :

CVE-2023-45286

It seem there is already a pull request on that topic.

Thanks for your amazing job ;)

alexwo commented 7 months ago

Well done! Hopefully, this pull request or an alternative solution can be incorporated 👍

jeevatkm commented 6 months ago

@jeromedoucet Thanks for reaching out. I have been traveling around on vacation days and will be back from vacation in the first week of January. I'm sorry for not checking my emails and notifications properly these days.

Let me check and the merge PR.

jeevatkm commented 6 months ago

745 PR is merged, making a release.