build: update golang.org/x/crypto to v0.56.0 to fix CVE-2026-78662 and CVE-2026-56855
CVE-2026-78662: a malicious peer could flood an undecided channel's incoming requests, deadlocking the whole connection in golang.org/x/crypto/ssh (GO-2026-6354) CVE-2026-56855: a malicious peer could send crafted messages on an established channel, deadlocking the whole connection in golang.org/x/crypto/ssh (GO-2026-6355)
This commit is contained in:
Reference in New Issue
Block a user