Skip to content

Conversation

guptas6est
Copy link

Description

Upgraded Kubernetes dependencies to v0.29.0 to patch CVE-2023-44487, which fixes the HTTP/2 Rapid Reset DoS vulnerability.
This update ensures Consul remains secure against potential denial-of-service (DoS) attacks caused by malicious HTTP/2 traffic.

Changes made in:

  • go.mod
  • go.sum

Testing & Reproduction steps


Links


PR Checklist

  • updated test coverage
  • external facing docs updated
  • appropriate backport labels added
  • not a security concern

PCI review checklist

  • I have documented a clear reason for, and description of, the change I am making.
  • If applicable, I've documented a plan to revert these changes if they require more than reverting the pull request.
  • If applicable, I've documented the impact of any changes to security controls.

@guptas6est guptas6est requested a review from a team as a code owner September 5, 2025 16:01
Copy link

hashicorp-cla-app bot commented Sep 5, 2025

CLA assistant check
All committers have signed the CLA.

@github-actions github-actions bot added the pr/dependencies PR specifically updates dependencies of project label Sep 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr/dependencies PR specifically updates dependencies of project

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant