Upgrade golang.org/x/image from v0.41.0 to v0.43.0 to remediate two vulnerabilities: CVE-2026-33813 (denial of service via malformed WEBP parsing, fixed in v0.42.0) and CVE-2026-46602 (missing limit on tile sizes in x/image/tiff, fixed in v0.43.0). The bump also pulls in golang.org/x/text v0.38.0 transitively. Signed-off-by: Émile Ré <emile@probo.com>
13 KiB
13 KiB