NO-ISSUE: Bump golang.org/x/crypto to v0.52.0#580
Conversation
Update golang.org/x/crypto from v0.49.0 to v0.52.0 to address CVE-2026-46597 (Denial of Service via crafted AES-GCM packet decoder inputs in golang.org/x/crypto/ssh). An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs. Note: golang.org/x/crypto/ssh is not directly imported by this component (indirect dependency only), so risk is LOW. Updating for compliance. CVSS: 7.5 (Important) Go Vuln DB: GO-2026-5013 Related: OCPBUGS-95516
|
Pipeline controller notification For optional jobs, comment This repository is configured in: LGTM mode |
|
@jkaurredhat: This pull request explicitly references no jira issue. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
📝 WalkthroughWalkthroughUpdated five indirect Possibly related issues
🚥 Pre-merge checks | ✅ 15✅ Passed checks (15 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@go.mod`:
- Line 126: Update the indirect golang.org/x/net dependency from v0.54.0 to
v0.55.0 or later in go.mod, then verify the module graph or dependency usage to
confirm whether the affected x/net packages are reachable and retain the
resolved version accordingly.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository YAML (base), Central YAML (inherited)
Review profile: CHILL
Plan: Enterprise
Run ID: 26be239c-672f-4515-992a-9fbae08a4474
⛔ Files ignored due to path filters (121)
go.sumis excluded by!**/*.sumvendor/golang.org/x/crypto/hkdf/hkdf.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/README.mdis excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/client_conn_pool.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/clientconn.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/config.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/http2.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/server.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/server_common.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/server_wrap.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/transport.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/transport_common.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/transport_wrap.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/writesched.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/writesched_common.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/writesched_priority_rfc7540.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/writesched_priority_rfc9218.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/writesched_random.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/writesched_roundrobin.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/idna/go118.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/idna/idna.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/idna/idna9.0.0.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/idna/pre_go118.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/idna/punycode.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/idna/tables10.0.0.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/idna/tables11.0.0.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/idna/tables12.0.0.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/idna/tables13.0.0.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/idna/tables15.0.0.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/idna/tables17.0.0.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/idna/tables9.0.0.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/idna/trie12.0.0.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/idna/trie13.0.0.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/internal/httpcommon/request.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/cpu/cpu.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/cpu/cpu_darwin_arm64_other.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/cpu/cpu_linux_riscv64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/cpu/cpu_loong64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/cpu/cpu_riscv64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/cpu/cpu_windows.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/cpu/cpu_windows_arm64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/cpu/zcpu_windows.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/affinity_linux.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/mkall.shis excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/mkerrors.shis excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/readv_unix.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/syscall_darwin.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/syscall_linux.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/syscall_linux_arm.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/syscall_linux_arm64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/syscall_linux_loong64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/syscall_linux_riscv64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/syscall_openbsd.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_386.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_amd64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_arm.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_arm64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_loong64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_mips.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_mips64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_mips64le.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_mipsle.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_ppc.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_ppc64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_ppc64le.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_riscv64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_s390x.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_sparc64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsyscall_linux.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsyscall_openbsd_386.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsyscall_openbsd_386.sis excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsyscall_openbsd_amd64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsyscall_openbsd_amd64.sis excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsyscall_openbsd_arm.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsyscall_openbsd_arm.sis excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsyscall_openbsd_arm64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsyscall_openbsd_arm64.sis excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsyscall_openbsd_mips64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsyscall_openbsd_mips64.sis excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsyscall_openbsd_ppc64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsyscall_openbsd_ppc64.sis excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsyscall_openbsd_riscv64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsyscall_openbsd_riscv64.sis excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_386.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_amd64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_arm.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_arm64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_loong64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_mips.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_mips64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_mips64le.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_mipsle.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_ppc.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_ppc64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_ppc64le.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_riscv64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_s390x.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsysnum_linux_sparc64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_386.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_amd64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_arm.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_arm64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_loong64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_mips.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_mips64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_mips64le.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_mipsle.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_ppc.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_ppc64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_ppc64le.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_riscv64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_s390x.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux_sparc64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/windows/dll_windows.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/windows/security_windows.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/windows/syscall_windows.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/windows/types_windows.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/windows/zsyscall_windows.gois excluded by!vendor/**,!**/vendor/**vendor/modules.txtis excluded by!vendor/**,!**/vendor/**
📒 Files selected for processing (1)
go.mod
| golang.org/x/crypto v0.52.0 // indirect | ||
| golang.org/x/exp v0.0.0-20260312153236-7ab1446f8b90 // indirect | ||
| golang.org/x/net v0.52.0 // indirect | ||
| golang.org/x/net v0.54.0 // indirect |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
go mod verify
govulncheck ./...
go list -m all | grep '^golang.org/x/'Repository: openshift/csi-operator
Length of output: 230
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
printf '\n== go.mod context ==\n'
nl -ba go.mod | sed -n '115,135p'
printf '\n== go.sum matches for golang.org/x/net ==\n'
rg -n '^golang.org/x/net ' go.sum || true
printf '\n== go.mod references to golang.org/x/net ==\n'
rg -n 'golang.org/x/net' go.mod go.sum || trueRepository: openshift/csi-operator
Length of output: 222
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
printf '\n== go.mod context ==\n'
sed -n '115,135p' go.mod
printf '\n== go.sum matches for golang.org/x/net ==\n'
rg -n '^golang.org/x/net ' go.sum || true
printf '\n== go.mod references to golang.org/x/net ==\n'
rg -n 'golang.org/x/net' go.mod go.sum || trueRepository: openshift/csi-operator
Length of output: 2623
🌐 Web query:
OSV golang.org/x/net v0.54.0 vulnerabilities fixed version 0.55.0 CVE-2026-39821
💡 Result:
CVE-2026-39821 is a security vulnerability in the idna package of the golang.org/x/net module, which was fixed in version 0.55.0 [1][2]. The vulnerability involves an improper input validation flaw in the ToASCII and ToUnicode functions [3][2]. These functions incorrectly accept Punycode-encoded labels that decode to ASCII-only labels (e.g., "xn--example-.com" incorrectly resolving to "example.com" instead of returning an error) [3][2]. This behavior can lead to privilege escalation, as an attacker could potentially bypass security controls that perform checks on an ASCII hostname before it is converted to Unicode [3][2]. This issue is tracked by Go as GO-2026-5026 [1][2]. Users are advised to upgrade to golang.org/x/net version 0.55.0 or later to mitigate this risk [4][2].
Citations:
- 1: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
- 2: https://osv.dev/vulnerability/GO-2026-5026
- 3: https://app.opencve.io/cve/CVE-2026-39821
- 4: https://intel.aikido.dev/cve/AIKIDO-2026-11036
🌐 Web query:
site:osv.dev golang.org/x/net v0.54.0 html vulnerability fixed version
💡 Result:
Version v0.54.0 of the golang.org/x/net package is affected by several HTML parsing vulnerabilities that can lead to XSS (cross-site scripting) attacks when processing and rendering arbitrary HTML [1][2][3][4][5]. These vulnerabilities are generally fixed in version v0.55.0 [1][2][3][4]. Specific vulnerabilities identified in the golang.org/x/net/html package include: - Incorrect handling of duplicate attributes (GO-2026-5030 / CVE-2026-27136) [1][6]. - Incorrect handling of character references in DOCTYPE nodes (GO-2026-5029) [2]. - Incorrect handling of HTML elements in foreign content (GO-2026-5027 / CVE-2026-42502) [3][4]. - Incorrect handling of namespaced elements in foreign content (CVE-2026-42506) [5]. To remediate these issues, users should update their dependency to at least version v0.55.0 [1][2][3][4].
Citations:
- 1: https://osv.dev/vulnerability/GO-2026-5030
- 2: https://osv.dev/vulnerability/GO-2026-5029
- 3: http://osv.dev/vulnerability/CVE-2026-42502
- 4: https://osv.dev/vulnerability/GO-2026-5027
- 5: https://test.osv.dev/vulnerability/CVE-2026-42506
- 6: https://osv.dev/vulnerability/CVE-2026-27136
Update golang.org/x/net to v0.55.0 or later. v0.54.0 is still listed by OSV as affected by CVE-2026-39821 and multiple x/net/html vulnerabilities fixed in v0.55.0. Since this is indirect, confirm the affected packages are actually reachable.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@go.mod` at line 126, Update the indirect golang.org/x/net dependency from
v0.54.0 to v0.55.0 or later in go.mod, then verify the module graph or
dependency usage to confirm whether the affected x/net packages are reachable
and retain the resolved version accordingly.
Source: Path instructions
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: jkaurredhat The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
@jkaurredhat: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Summary
This PR updates
golang.org/x/cryptofromv0.49.0tov0.52.0to address CVE-2026-46597 (Denial of Service via crafted AES-GCM packet decoder inputs ingolang.org/x/crypto/ssh).An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Note:
golang.org/x/crypto/sshis not directly imported by the csi-operator (indirect dependency only), so the risk is LOW. Updating for security compliance.