GHSA-967g-cjx4-h7j6: Duplicate Advisory: go-codec-dagpb vulnerable to panic when decoding invalid blocks
(updated )
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-g3vv-g2j5-45f2. This link is maintained to preserve external references.
Original Description
go-codec-dagpb is an implementation of the DAG-PB spec for Go. The dag-pb codec can panic when decoding invalid blocks. This issue has been patched in version 1.3.1.
References
Code Behaviors & Features
Detect and mitigate GHSA-967g-cjx4-h7j6 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →