Skip to content

AIRSHIP-4953 [CRITICAL] 3 vulnerability fixes (uswitch/vault-creds) - #44

Merged
John-Holden merged 2 commits into
masterfrom
reactor/vuln-fix/go-mod-updates-2026-07-20
Jul 22, 2026
Merged

John-Holden merged 2 commits into
masterfrom
reactor/vuln-fix/go-mod-updates-2026-07-20

Conversation

@reactor-agent-platform

@reactor-agent-platform reactor-agent-platform Bot commented Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

Vulnerabilities

CVE-2026-39821 — CRITICAL (CVSS 3.1: 9.6, NVD; sweep reported 9.3)
Package: golang.org/x/net/idna 0.52.0 → 0.54.0
The ToASCII/ToUnicode functions in golang.org/x/net/idna incorrectly accept Punycode-encoded labels that decode to an ASCII-only label (e.g. ToUnicode("xn--example-.com") incorrectly returns "example.com"). Programs that perform privilege checks on the ASCII hostname before converting to Unicode can be tricked into granting access to a different, unintended hostname — a privilege-escalation vector.

CVE-2026-33814 — HIGH (CVSS 3.1: 7.5, NVD; sweep reported 8.7)
Package: golang.org/x/net/http2 0.52.0 → 0.53.0
When processing HTTP/2 SETTINGS frames, the http2 transport enters an infinite loop writing CONTINUATION frames if the peer sends SETTINGS_MAX_FRAME_SIZE with a value of 0 — a denial-of-service vector.

CVE-2026-39822 — HIGH (CVSS 3.1: 7.8, NVD; sweep reported 8.5)
Package: Go standard library os (std/os) 1.25.11 → 1.25.12 (also fixed in 1.26.5, 1.27.0-rc.2)
On Unix, opening a file inside an os.Root improperly follows symlinks outside the root when the final path component is a symlink and the path ends in / (e.g. root.Open("symlink/") opens the symlink target even when it points outside the root).

golang.org/x/net is a transitive dependency (already listed // indirect in go.mod); Go's MVS resolution means a direct version bump is the correct and only mechanism here (no override needed).

Changes

  • Bumped golang.org/x/net 0.52.0 → 0.53.0 (fixes CVE-2026-33814), then → 0.54.0 (fixes CVE-2026-39821), each via go get/go mod tidy. This also pulled forward the golang.org/x/crypto, golang.org/x/sys, golang.org/x/term, and golang.org/x/text releases in the same x/ train that go mod tidy selects as part of MVS resolution for the new x/net version — not independent bumps.
  • go 1.25.7 retained as the module's minimum (required by github.com/hashicorp/vault/sdk@v0.25.1) and added toolchain go1.25.12 to go.mod, per the active-cycle Go toolchain rule: cycle 1.25 is still active (not EOL) per endoflife.date, and 1.25.12 is its latest patch and resolves CVE-2026-39822. 1.26 is also active but 1.25 is the lowest active cycle at or above the fix's minor version, so the module's go directive stays at 1.25.
  • Outstanding: .github/workflows/push.yaml still pins actions/setup-go@v5 with explicit go-version: "1.25" (test job) and go-version: "1.24" (build job) rather than actions/setup-go@v6 with go-version-file: go.mod. I attempted this alignment but the push token available to this automation lacks the workflow OAuth scope needed to update files under .github/workflows/ (refusing to allow a Personal Access Token to create or update workflow ... without workflow scope), so it could not be committed. In practice this is mitigated by Go's GOTOOLCHAIN=auto default: because go.mod now declares toolchain go1.25.12, any go build/go test invocation in CI will auto-download and use go1.25.12 regardless of which SDK setup-go installed, so the patched toolchain is what actually builds/tests/ships. Still, a maintainer with workflow scope should apply the go-version-file: go.mod change to keep CI's declared toolchain in sync and to move the build job off the now-EOL 1.24 cycle explicitly.

Verification

  • go build ./... — passed
  • go vet ./... — passed, no findings
  • go test -v -cover $(go list ./... | grep -v /vendor) — passed (pkg/kube, pkg/vault; cmd and pkg/metrics have no test files, pre-existing)
  • go list -m golang.org/x/net — confirms v0.54.0 resolved
  • go version after go mod tidy — confirms go1.25.12 toolchain resolved and used
  • gofmt -l . reports the same 4 pre-existing unformatted files on master as on this branch (cmd/main.go, pkg/kube/kube.go, pkg/vault/factory.go, pkg/vault/manager.go) — unrelated to this change, not introduced here

Testing gaps

No test coverage exercises idna, http2, or os.Root code paths directly (they're pulled in transitively via k8s.io/client-go, hashicorp/vault, etc.), so the fix is verified by dependency resolution and the existing test suite passing, not by a targeted regression test.

Outstanding questions

  • Should a maintainer with workflow-scope credentials follow up to update .github/workflows/push.yaml (actions/setup-go@v6 + go-version-file: go.mod), given this automation cannot push workflow file changes?

Linear tickets

AIRSHIP-4953

@reactor-agent-platform reactor-agent-platform Bot changed the title [CRITICAL] 3 vulnerability fixes (uswitch/vault-creds) AIRSHIP-4953 [CRITICAL] 3 vulnerability fixes (uswitch/vault-creds) Jul 20, 2026
@linear-code

linear-code Bot commented Jul 20, 2026

Copy link
Copy Markdown

AIRSHIP-4953

@uswitch uswitch deleted a comment from reactor-agent-platform Bot Jul 22, 2026
@John-Holden
John-Holden merged commit 00bacf6 into master Jul 22, 2026
3 checks passed
@DewaldV
DewaldV deleted the reactor/vuln-fix/go-mod-updates-2026-07-20 branch July 22, 2026 13:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant