Package
jaeger-1-anonymizer-compat
Component
stdlib
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
GO-2026-6090 (CVE-2026-56862) is a high-severity denial-of-service in the Go standard library's crypto/tls package: a malicious client can send a stream of post-handshake KeyUpdate messages to force the server into unbounded key-derivation work. It affects Go toolchains before 1.25.13 (and 1.26.x before 1.26.6, and 1.27 before 1.27.0-rc.3). The affected Jaeger 1.76.0 build was compiled with Go 1.25.11, which is within the vulnerable range.
The Jaeger 1.x line reached end-of-life on 2025-12-31 and is no longer maintained, so the fixed Go toolchain will not be applied to the 1.x images. Users should migrate to the maintained Jaeger 2.x images, which are built with a current, unaffected Go toolchain.
References:
Status