[GH-ISSUE #4919] Request to publish new release with updated Go version (≥ 1.23.12) #3880

Closed
opened 2026-05-05 14:28:46 -06:00 by gitea-mirror · 0 comments
Owner

Originally created by @dorki on GitHub (Aug 9, 2025).
Original GitHub issue: https://github.com/fatedier/frp/issues/4919

Bug Description

The latest published release is built with Go 1.23.8, which contains known vulnerabilities:

CVE-2025-47907 – fixed in Go 1.23.12
CVE-2025-4674 – fixed in Go 1.23.11

For security reasons, it would be great to publish a new release of frp built with at least Go 1.23.12 to address these issues.

This will help downstream users avoid exposure to these vulnerabilities without having to build from source.

Thanks for your work on this project!

frpc Version

0.63.0

frps Version

0.63.0

Affected area

  • Docs
  • Installation
  • Performance and Scalability
  • Security
  • User Experience
  • Test and Release
  • Developer Infrastructure
  • Client Plugin
  • Server Plugin
  • Extensions
  • Others
Originally created by @dorki on GitHub (Aug 9, 2025). Original GitHub issue: https://github.com/fatedier/frp/issues/4919 ### Bug Description The latest published release is built with Go 1.23.8, which contains known vulnerabilities: CVE-2025-47907 – fixed in Go 1.23.12 CVE-2025-4674 – fixed in Go 1.23.11 For security reasons, it would be great to publish a new release of frp built with at least Go 1.23.12 to address these issues. This will help downstream users avoid exposure to these vulnerabilities without having to build from source. Thanks for your work on this project! ### frpc Version 0.63.0 ### frps Version 0.63.0 ### Affected area - [ ] Docs - [ ] Installation - [ ] Performance and Scalability - [x] Security - [ ] User Experience - [ ] Test and Release - [ ] Developer Infrastructure - [ ] Client Plugin - [ ] Server Plugin - [ ] Extensions - [ ] Others
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: github-starred/frp#3880
No description provided.