Skip to content

fix(deps): bump golang.org/x/crypto to v0.55.0 for CVE-2026-56854 - #91

Merged
zsio merged 2 commits into
mainfrom
fix/x-crypto-cve-2026-56854
Sep 9, 2026
Merged

zsio merged 2 commits into
mainfrom
fix/x-crypto-cve-2026-56854

Conversation

@zsio

@zsio zsio commented Sep 9, 2026

Copy link
Copy Markdown
Owner

背景

v0.1.17 的 Release workflow 中 scan-docker 失败:Trivy 在镜像内的 Go 二进制中发现 golang.org/x/crypto v0.53.0 命中 CVE-2026-56854(CRITICAL,x/crypto/ssh 认证绕过,fixed in v0.55.0)。Alpine 基础层干净,仅 gobinary 层有这一条发现。

scan-docker 对 stable tag(无 -)设置 exit-code: 1,CRITICAL/HIGH 发现即失败;beta tag 非阻塞,因此此前的 beta 发布未暴露该问题。govulncheck 在 9/4 的 main CI 通过是因为当时通告尚未进入漏洞库。

改动

  • golang.org/x/crypto v0.53.0 → v0.55.0,连带 go mod tidy 收敛的 x/ 传递依赖(net/sys/term/text/sync 小版本)。

验证

  • go build ./...、go vet ./...、go test ./... 通过。
  • 本地以 CI 同口径(Trivy 0.70.0,severity CRITICAL,HIGH,未过滤 unfixed)扫描重编的二进制:0 发现。
  • govulncheck ./...(与 CI 相同命令):可达漏洞 0。
  • pkg/p2p 的 TestSessionIPv6OnlyLoopback 在全量并发下偶发失败,单独跑与未升级的 main 上均复现不了,属既有 flaky,与本改动无关。

后续

合并后建议直接发 v0.1.18 替换 stable 通道上的 v0.1.17(该 release 已发布且镜像带 CRITICAL 漏洞,不建议改写已发布 tag)。

Trivy image scan flagged CRITICAL CVE-2026-56854 (x/crypto/ssh auth
bypass) in the v0.1.17 release image; scan-docker gates stable tags on
CRITICAL,HIGH findings. Upgrade x/crypto and its transitive x/ module
closure. Local trivy rescan of the rebuilt binary is clean and
govulncheck reports 0 reachable vulnerabilities.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-09T04:13:33.565411Z 05af872 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

x/vuln v1.8.0 requires go >= 1.26.0 while CI runs go 1.25.13 with
GOTOOLCHAIN=local, so the floating @latest install broke the
govulncheck job. Pin to the last release compatible with go 1.25;
the vulnerability database is fetched at runtime so detection stays
current.
@zsio
zsio merged commit be73bc4 into main Sep 9, 2026
11 checks passed
@zsio
zsio deleted the fix/x-crypto-cve-2026-56854 branch September 9, 2026 10:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant