Skip to content

Fix 4 CVEs (CVE-2026-56864, CVE-2026-56865, CVE-2026-84304, ...) - #194

Open
rhwa-cve-pr-creator[bot] wants to merge 1 commit into
medik8s:mainfrom
weshayutin:cve-fix/main/20260930-1
Open

rhwa-cve-pr-creator[bot] wants to merge 1 commit into
medik8s:mainfrom
weshayutin:cve-fix/main/20260930-1

Conversation

@rhwa-cve-pr-creator

Copy link
Copy Markdown

CVE Fixes

Automated scan remediated 4 of 4 fixable Go dependency CVE(s) in medik8s/node-maintenance-operator on branch main.

CVE Severity Package Fixed Version Description
CVE-2026-56864 HIGH golang.org/x/mod 0.40.0 golang.org/x/mod/sumdb: golang.org/x/mod/sumdb: Integrity bypass via malicious GOSUMDB
CVE-2026-56865 HIGH golang.org/x/mod 0.40.0 golang.org/x/mod/sumdb/tlog: golang.org/x/mod/sumdb/tlog: Supply chain compromise via transparency log tile verification bypass
CVE-2026-84304 HIGH google.golang.org/grpc 1.85.0-dev.0.20260825072537-93e31b48545e gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...
CVE-2026-84445 HIGH google.golang.org/grpc 1.85.0-dev.0.20260825072537-93e31b48545e google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests

How this was fixed

  • One go get for all vulnerable dependencies, using the highest reported fixed version per package
  • go mod tidy to clean up
  • go mod vendor to update vendored dependencies (if applicable)

Generated by cve-scan pipeline

@openshift-ci
openshift-ci Bot requested review from abrugaro and mshitrit September 30, 2026 17:15
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 5134699d-c138-42ac-b980-0a5f33cc4ddf

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@mshitrit mshitrit left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

2 Nits:

an unreleased grpc version is used where there are multiple existing stable grpc versions which also fixes this vulnerability (i.e v1.83.2 and v1.84.0. ect... )
a higher go version is required for the vulnerability fix (e.g 1.26.6+) even though it's not relevant downstream (main priority) as the version is overridden it still means that upstream fix isn't complete.

/hold
holding until test setup is done for NMO so we can verify E2E tests.

@openshift-ci

openshift-ci Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: mshitrit, rhwa-cve-pr-creator[bot]

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved label Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant