Skip to content

fix(security): go security fixes (2026-09-14) - #1514

Open
github-actions[bot] wants to merge 1 commit into
newjitsufrom
security/fix-go-2026-09-14
Open

github-actions[bot] wants to merge 1 commit into
newjitsufrom
security/fix-go-2026-09-14

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Included fixes

  • CVE-2026-84445 (high): gRPC-Go xDS missing authority/Host-header denial of service — google.golang.org/grpc 1.83.1 → 1.83.2
  • CVE-2026-53495 (moderate): containerd CRI ExecSync goroutine-leak denial of service — github.com/containerd/containerd/v2 2.2.5 → 2.2.8

Risks

None. The included changes are patch updates; transitive dependencies moved only forward as required by the patched modules.

Skipped (already satisfied / would downgrade)

Skipped (build incompatibility)

  • CVE-2026-61711 / GHSA-7236-3392-c5c6: github.com/moby/buildkit 0.29.0 → 0.31.1 fails to build because github.com/docker/compose/v5@v5.1.2 imports the removed package github.com/moby/buildkit/util/tracing/env. The change was reverted.

Verification

  • go -C bulker work sync
  • go -C bulker/ build ./... (13 modules)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants