Skip to content

build(deps): bump google.golang.org/grpc to v1.83.1 - #10

Merged
zzzz465 merged 1 commit into
mainfrom
feature/bump-grpc-1.83.1
Sep 2, 2026
Merged

build(deps): bump google.golang.org/grpc to v1.83.1#10
zzzz465 merged 1 commit into
mainfrom
feature/bump-grpc-1.83.1

Conversation

@zzzz465

@zzzz465 zzzz465 commented Sep 2, 2026

Copy link
Copy Markdown

bump grpc version

Fixes GHSA-vp52-pcj8-j9qc / CVE-2026-84304 (high): an unauthenticated
remote peer can fragment a gRPC stream into millions of tiny HTTP/2 DATA
frames. Each fragment carries per-frame tracking and queue allocation, so
the heap grows far beyond the flow-control window and the process can be
driven to OOM. Affects grpc-go <= 1.83.0; fixed in 1.83.1 by receive
buffer compaction.

This matters here because spire-server's agent endpoint has to accept
connections from agents that have not attested yet, so the HTTP/2 layer
is reachable before any gRPC-level authentication.

Upstream carries the same version on main after the v1.15.3 release, so
this should not conflict on the next upstream merge.

go.mod and go.sum only; no other dependency moved. spire-agent builds.

Signed-off-by: jungooji <46273764+zzzz465@users.noreply.github.com>
@zzzz465
zzzz465 merged commit 2215790 into main Sep 2, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant