Update golang.org/x/net to v0.53.0
Fixes CVE-2026-33814 (golang/go#78476): HTTP/2 Transport hangs indefinitely when a peer sends a SETTINGS frame with MaxFrameSize=0. This is reachable from kube-apiserver's OIDC, admission webhook, and aggregated API client paths. Kubernetes-commit: 12a2470693d86f63f4614048ffdd43dc393dd7e0
D
Davanum Srinivas committed
f289600a5d33a20298f7d259286f75b930b92604
Parent: 8a5a2f6
Committed by Kubernetes Publisher <k8s-publishing-bot@users.noreply.github.com>
on 4/24/2026, 1:36:05 AM