Skip to content

Commit a768472

Browse files
vmrh21claude
andcommitted
fix(cve): cve-2026-33186 - grpc-go auth bypass
update google.golang.org/grpc from v1.75.1 to v1.79.3 to resolve authorization bypass due to improper http/2 path validation. resolves: rhoaieng-55311 co-authored-by: claude opus 4.6 <noreply@anthropic.com>
1 parent 855933f commit a768472

2 files changed

Lines changed: 64 additions & 67 deletions

File tree

maas-api/go.mod

Lines changed: 20 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -14,8 +14,7 @@ require (
1414
github.com/openai/openai-go/v2 v2.3.1
1515
github.com/stretchr/testify v1.11.1
1616
go.uber.org/zap v1.27.0
17-
golang.org/x/sync v0.18.0
18-
gopkg.in/yaml.v3 v3.0.1
17+
golang.org/x/sync v0.19.0
1918
k8s.io/api v0.34.1
2019
k8s.io/apimachinery v0.34.1
2120
k8s.io/client-go v0.34.1
@@ -25,11 +24,11 @@ require (
2524
)
2625

2726
require (
28-
cel.dev/expr v0.24.0 // indirect
27+
cel.dev/expr v0.25.1 // indirect
2928
cloud.google.com/go v0.121.6 // indirect
3029
cloud.google.com/go/auth v0.16.4 // indirect
3130
cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
32-
cloud.google.com/go/compute/metadata v0.8.0 // indirect
31+
cloud.google.com/go/compute/metadata v0.9.0 // indirect
3332
cloud.google.com/go/iam v1.5.2 // indirect
3433
cloud.google.com/go/monitoring v1.24.2 // indirect
3534
cloud.google.com/go/storage v1.56.0 // indirect
@@ -38,7 +37,7 @@ require (
3837
github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2 // indirect
3938
github.com/Azure/azure-sdk-for-go/sdk/storage/azblob v1.6.2 // indirect
4039
github.com/AzureAD/microsoft-authentication-library-for-go v1.5.0 // indirect
41-
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.29.0 // indirect
40+
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.30.0 // indirect
4241
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.53.0 // indirect
4342
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.53.0 // indirect
4443
github.com/aws/aws-sdk-go v1.55.6 // indirect
@@ -47,18 +46,18 @@ require (
4746
github.com/bytedance/sonic/loader v0.2.4 // indirect
4847
github.com/cespare/xxhash/v2 v2.3.0 // indirect
4948
github.com/cloudwego/base64x v0.1.5 // indirect
50-
github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 // indirect
49+
github.com/cncf/xds/go v0.0.0-20251210132809-ee656c7534f5 // indirect
5150
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
5251
github.com/emicklei/go-restful/v3 v3.13.0 // indirect
53-
github.com/envoyproxy/go-control-plane/envoy v1.32.4 // indirect
54-
github.com/envoyproxy/protoc-gen-validate v1.2.1 // indirect
52+
github.com/envoyproxy/go-control-plane/envoy v1.36.0 // indirect
53+
github.com/envoyproxy/protoc-gen-validate v1.3.0 // indirect
5554
github.com/evanphx/json-patch/v5 v5.9.11 // indirect
5655
github.com/felixge/httpsnoop v1.0.4 // indirect
5756
github.com/fsnotify/fsnotify v1.9.0 // indirect
5857
github.com/fxamacker/cbor/v2 v2.9.0 // indirect
5958
github.com/gabriel-vasile/mimetype v1.4.9 // indirect
6059
github.com/gin-contrib/sse v1.1.0 // indirect
61-
github.com/go-jose/go-jose/v4 v4.1.1 // indirect
60+
github.com/go-jose/go-jose/v4 v4.1.3 // indirect
6261
github.com/go-logr/logr v1.4.3 // indirect
6362
github.com/go-logr/stdr v1.2.2 // indirect
6463
github.com/go-openapi/jsonpointer v0.21.2 // indirect
@@ -98,17 +97,16 @@ require (
9897
github.com/prometheus/common v0.66.1 // indirect
9998
github.com/prometheus/procfs v0.17.0 // indirect
10099
github.com/spf13/pflag v1.0.10 // indirect
101-
github.com/spiffe/go-spiffe/v2 v2.5.0 // indirect
100+
github.com/spiffe/go-spiffe/v2 v2.6.0 // indirect
102101
github.com/tidwall/gjson v1.18.0 // indirect
103102
github.com/tidwall/match v1.1.1 // indirect
104103
github.com/tidwall/pretty v1.2.1 // indirect
105104
github.com/tidwall/sjson v1.2.5 // indirect
106105
github.com/twitchyliquid64/golang-asm v0.15.1 // indirect
107106
github.com/ugorji/go/codec v1.3.0 // indirect
108107
github.com/x448/float16 v0.8.4 // indirect
109-
github.com/zeebo/errs v1.4.0 // indirect
110108
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
111-
go.opentelemetry.io/contrib/detectors/gcp v1.36.0 // indirect
109+
go.opentelemetry.io/contrib/detectors/gcp v1.39.0 // indirect
112110
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.61.0 // indirect
113111
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.62.0 // indirect
114112
go.opentelemetry.io/otel v1.40.0 // indirect
@@ -120,23 +118,24 @@ require (
120118
go.yaml.in/yaml/v2 v2.4.2 // indirect
121119
go.yaml.in/yaml/v3 v3.0.4 // indirect
122120
golang.org/x/arch v0.18.0 // indirect
123-
golang.org/x/crypto v0.45.0 // indirect
124-
golang.org/x/net v0.47.0 // indirect
125-
golang.org/x/oauth2 v0.30.0 // indirect
121+
golang.org/x/crypto v0.46.0 // indirect
122+
golang.org/x/net v0.48.0 // indirect
123+
golang.org/x/oauth2 v0.34.0 // indirect
126124
golang.org/x/sys v0.40.0 // indirect
127-
golang.org/x/term v0.37.0 // indirect
128-
golang.org/x/text v0.31.0 // indirect
125+
golang.org/x/term v0.38.0 // indirect
126+
golang.org/x/text v0.32.0 // indirect
129127
golang.org/x/time v0.12.0 // indirect
130128
gomodules.xyz/jsonpatch/v2 v2.5.0 // indirect
131129
google.golang.org/api v0.247.0 // indirect
132130
google.golang.org/genproto v0.0.0-20250603155806-513f23925822 // indirect
133-
google.golang.org/genproto/googleapis/api v0.0.0-20250818200422-3122310a409c // indirect
134-
google.golang.org/genproto/googleapis/rpc v0.0.0-20250826171959-ef028d996bc1 // indirect
135-
google.golang.org/grpc v1.75.1 // indirect
136-
google.golang.org/protobuf v1.36.8 // indirect
131+
google.golang.org/genproto/googleapis/api v0.0.0-20251202230838-ff82c1b0f217 // indirect
132+
google.golang.org/genproto/googleapis/rpc v0.0.0-20251202230838-ff82c1b0f217 // indirect
133+
google.golang.org/grpc v1.79.3 // indirect
134+
google.golang.org/protobuf v1.36.10 // indirect
137135
gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect
138136
gopkg.in/go-playground/validator.v9 v9.31.0 // indirect
139137
gopkg.in/inf.v0 v0.9.1 // indirect
138+
gopkg.in/yaml.v3 v3.0.1 // indirect
140139
k8s.io/klog/v2 v2.130.1 // indirect
141140
k8s.io/kube-openapi v0.0.0-20250814151709-d7b6acb124c3 // indirect
142141
knative.dev/serving v0.44.0 // indirect

0 commit comments

Comments
 (0)