Skip to content

Fix 5 CVEs (CVE-2026-56854, CVE-2026-56852, CVE-2026-84304, ...) - #67

Open
oadp-rebasebot-app[bot] wants to merge 1 commit into
openshift:oadp-1.6from
oadp-rebasebot:cve-fix/oadp-1.6/20260921-1
Open

oadp-rebasebot-app[bot] wants to merge 1 commit into
openshift:oadp-1.6from
oadp-rebasebot:cve-fix/oadp-1.6/20260921-1

Conversation

@oadp-rebasebot-app

Copy link
Copy Markdown

CVE Fixes

Automated scan remediated 5 of 5 fixable Go dependency CVE(s) in openshift/restic on branch oadp-1.6.

CVE Severity Package Fixed Version Description
CVE-2026-56854 HIGH golang.org/x/crypto 0.55.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions
CVE-2026-56852 HIGH golang.org/x/text 0.41.0 golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
CVE-2026-84304 HIGH google.golang.org/grpc 1.85.0-dev.0.20260825072537-93e31b48545e gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...
CVE-2026-84445 HIGH google.golang.org/grpc 1.85.0-dev.0.20260825072537-93e31b48545e google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests
GHSA-hrxh-6v49-42gf HIGH google.golang.org/grpc 1.85.0-dev.0.20260825072537-93e31b48545e gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

How this was fixed

  • One go get for all vulnerable dependencies, using the highest reported fixed version per package
  • go mod tidy to clean up

Generated by cve-scan pipeline

@coderabbitai

coderabbitai Bot commented Sep 21, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: c6e37b99-67d1-4fcd-a3a6-9ee354c997d7

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@openshift-ci openshift-ci Bot added the needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. label Sep 21, 2026
@openshift-ci

openshift-ci Bot commented Sep 21, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: oadp-rebasebot-app[bot]

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci

openshift-ci Bot commented Sep 21, 2026

Copy link
Copy Markdown

Hi @oadp-rebasebot-app[bot]. Thanks for your PR.

I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants