Skip to content

Security: Fix multiple CVEs — grpc, x/net, x/text, hashicorp, cloudevents, prometheus (release-0.8.x) - #2937

Closed
theakshaypant wants to merge 1 commit into
release-0.8.xfrom
fix/cve-stdlib-grpc-text-net-release-0.8.x-attempt-1
Closed

theakshaypant wants to merge 1 commit into
release-0.8.xfrom
fix/cve-stdlib-grpc-text-net-release-0.8.x-attempt-1

Conversation

@theakshaypant

Copy link
Copy Markdown
Member

Summary

This PR fixes 6 CVEs on the release-0.8.x branch by upgrading affected dependencies to their patched versions.

CVE Details

CVE / Advisory Package Old Version New Version Severity
CVE-2026-33186 / GHSA-p77j-4mvh-x3m3 google.golang.org/grpc v1.44.0 v1.82.1 CRITICAL
GO-2026-5970 golang.org/x/text v0.3.7 v0.40.0 HIGH
GO-2026-5026 / GO-2026-4918 golang.org/x/net old v0.57.0 HIGH
CVE-2024-6104 / GO-2024-2947 github.com/hashicorp/go-retryablehttp v0.6.8 v0.7.7 MEDIUM
GO-2024-2618 github.com/cloudevents/sdk-go/v2 v2.8.0 v2.15.2 MEDIUM
GO-2022-0322 github.com/prometheus/client_golang v1.11.0 v1.11.1 LOW

CVE-2026-33186 (Critical): gRPC-Go authorization bypass via missing leading slash in :path.

GO-2026-5970: golang.org/x/text vulnerability affecting Unicode processing.

GO-2026-5026/GO-2026-4918: golang.org/x/net vulnerabilities in HTTP/2 and network handling.

CVE-2024-6104: hashicorp/go-retryablehttp logs sensitive Authorization headers.

GO-2024-2618: CloudEvents SDK vulnerability.

GO-2022-0322: Prometheus client_golang HTTP/2 vulnerability.

Changes Made

  • Updated go.mod to use patched dependency versions
  • Ran go mod tidy && go mod verify
  • Updated vendor directory via go mod vendor
  • Build verified: go build ./... passes ✅
  • Unit tests: go test ./pkg/... passes (1 pre-existing gitlab test failure unrelated to this change)

Test Results

Status: ✅ Build passes

govulncheck post-fix: CVE-2026-33186, GO-2026-5970, GO-2026-5026, GO-2026-4918, GO-2024-2947, GO-2024-2618, GO-2022-0322 — all resolved ✅

Remaining: 11 Go stdlib CVEs require Go toolchain 1.26.6 — not applicable to this old release line using go 1.17.

Jira Issues

Resolves: SRVKP-12834

Risk Assessment

Risk: Medium — grpc upgrade spans many versions (v1.44 → v1.82) but maintains backward compatibility. Build and unit tests pass.


🤖 Generated by CVE Fixer Workflow

Fixes the following CVEs on release-0.8.x:

- CVE-2026-33186 (GHSA-p77j-4mvh-x3m3): gRPC-Go authorization bypass
  google.golang.org/grpc v1.44.0 → v1.82.1

- CVE-2026-5970 (GO-2026-5970): golang.org/x/text vulnerability
  golang.org/x/text v0.3.7 → v0.40.0

- GO-2026-5026 / GO-2026-4918: golang.org/x/net vulnerabilities
  golang.org/x/net → v0.57.0

- CVE-2024-6104 (GO-2024-2947): hashicorp/go-retryablehttp info leak
  github.com/hashicorp/go-retryablehttp v0.6.8 → v0.7.7

- GO-2024-2618: cloudevents/sdk-go vulnerability
  github.com/cloudevents/sdk-go/v2 v2.8.0 → v2.15.2

- GO-2022-0322: prometheus/client_golang vulnerability
  github.com/prometheus/client_golang v1.11.0 → v1.11.1

Resolves: SRVKP-12834

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
@theakshaypant
theakshaypant deleted the fix/cve-stdlib-grpc-text-net-release-0.8.x-attempt-1 branch August 25, 2026 07:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant