Release binary built with outdated Go toolchain

Author: mkhoroshevCreated Aug 22, 2026Updated Aug 22, 2026
Labels反馈问题

问题描述

I ran Trivy against the cfst_linux_amd64 v2.3.5 binary and found 22 stdlib CVEs, including CVE-2025-68121 (CRITICAL, crypto/tls certificate validation), fixed in Go 1.24.13/1.25.7/1.26.0-rc.3. Buildinfo shows it was compiled with go1.24.5.

I know an older toolchain (v1.20) is kept intentionally for legacy-OS builds — this is about the main Linux release specifically. Would a rebuild with a newer 1.24.x+ point release be feasible?

Thanks for the project!

trivy.md

软件版本

v2.3.5

附加截图

No response

Source: XIU2/CloudflareSpeedTest