-
Notifications
You must be signed in to change notification settings - Fork 17
OCPBUGS-104317: Bump golang.org/x/net to v0.50.0-sec.4 #103
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Large diffs are not rendered by default.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift
🧩 Analysis chain
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 336
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 245
🌐 Web query:
github.com/openshift-sustaining/net v0.50.0-sec.4 module release retracted license security fixes💡 Result:
The github.com/openshift-sustaining/net module, including version v0.50.0-sec.4, is a fork of the upstream golang.org/x/net repository maintained by Red Hat for OpenShift [1][2]. It is used specifically to provide security backports while avoiding mandatory Go toolchain upgrades that would otherwise be required by direct upstream updates [2][3][4]. Key points regarding this module and version: Purpose: These forks are used in OpenShift to address security vulnerabilities (such as CVE-2026-25681) in older release branches [2][3][5]. By using a replace directive in go.mod, developers can incorporate specific security fixes without needing to upgrade the entire Go toolchain to the version required by the latest upstream golang.org/x/net [2][3][5]. Status: There is no indication that v0.50.0-sec.4 has been retracted. It is actively being integrated into current OpenShift release streams, such as 4.22.0 [1][6][7]. License and Security: As these are forks of the standard golang.org/x/net library, they typically maintain the upstream license. However, because they are custom-maintained forks used as a supply-chain bridge, they are subject to internal OpenShift security review processes [5]. Documentation for these forks emphasizes that they are intended for sustaining older versions where a full toolchain migration is not feasible [2][3][5]. For implementation, these modules are applied in go.mod files using the following pattern [1][2]: go mod edit -replace golang.org/x/net=github.com/openshift-sustaining/net@v0.50.0-sec.4 go mod tidy && go mod vendor Users should verify the current status of these dependencies within their specific OpenShift release branch by checking the official OpenShift GitHub repositories and associated Jira tickets (e.g., OCPBUGS-96686) [1][5].
Citations:
🌐 Web query:
OSV golang.org/x/crypto v0.48.0 vulnerabilities fixed version💡 Result:
The version v0.48.0 of golang.org/x/crypto is affected by multiple security vulnerabilities [1][2]. These vulnerabilities were addressed in version v0.52.0 [3][4][5]. To resolve these security issues, you should upgrade your dependency to at least version v0.52.0 or later [3][4][6]. The vulnerabilities addressed in v0.52.0 include, but are not limited to: - Various issues in the ssh package, such as bypasses of certificate restrictions, server panics, memory leaks leading to Denial of Service (DoS), and infinite loops [3][4][2]. - Security issues in ssh/agent, including the failure to enforce key constraints and susceptibility to panics from pathological inputs [3][4][5][2]. - Authentication bypasses in ssh/knownhosts due to unenforced
@revokedstatus [3][4][7]. - Authorization bypasses related to VerifiedPublicKeyCallback permissions [3][4]. For a complete list of vulnerabilities fixed in v0.52.0, you can refer to the official Go security announcements or the Open Source Vulnerabilities (OSV) database [4][8][5].Citations:
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 38205
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 3772
Resolve the vulnerable dependency and document the prerelease exception.
golang.org/x/crypto v0.48.0remains selected and has known vulnerabilities fixed inv0.52.0. Update it and regeneratego.sumandvendor.v0.50.0-sec.4is a published prerelease tag. Use a stable release with the required fixes, or document an approved exception with license, retraction, SBOM, provenance, and signing evidence.🤖 Prompt for AI Agents
Source: Path instructions
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 312
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 227
🌐 Web query:
OSV GO-2026-5028 golang.org/x/net affected versions fixed versions💡 Result:
GO-2026-5028 is a security vulnerability in the golang.org/x/net package, specifically affecting the html subpackage [1][2]. Affected versions include all versions prior to v0.55.0 [1][3]. The vulnerability is fixed in version v0.55.0 [1][4]. The vulnerability, identified as CVE-2026-25680, involves a denial-of-service (DoS) issue where parsing arbitrary HTML can consume excessive CPU time [1][2][4]. It affects the following symbols in the golang.org/x/net/html package: Parse, ParseFragment, ParseFragmentWithOptions, ParseWithOptions, and parser.parse [1][5][3].
Citations:
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 14799
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 1138
🌐 Web query:
github.com/openshift-sustaining/net v0.50.0-sec.4 security fixes x/net💡 Result:
The repository github.com/openshift-sustaining/net is a fork of the upstream golang.org/x/net maintained by Red Hat for OpenShift, used to backport security fixes while avoiding mandatory Go toolchain version upgrades [1][2][3]. The version v0.50.0-sec.4 is an OpenShift-specific patch release [4][5]. It is used to apply necessary security updates to the golang.org/x/net library without requiring components to upgrade to the upstream v0.50.0+ versions, which may necessitate a newer Go compiler toolchain [1][2][3]. Key points regarding this usage: * Purpose: It allows OpenShift components (such as the VMware vSphere CSI driver and the oc CLI) to incorporate critical security patches for x/net dependencies while maintaining compatibility with older, project-specific Go compiler versions (e.g., 1.23 or 1.24) [1][2][3]. * Application: It is typically applied in Go projects using the go mod edit -replace directive, which redirects the golang.org/x/net module to the openshift-sustaining/net fork [4][1][3]. * Context: These sustaining versions often bundle specific fixes, such as those related to CVE-2026-25681 (XSS in golang.org/x/net/html), among other maintenance updates [1][2][3]. The -sec.4 iteration specifically includes updates related to OCPBUGS-96686, which have been incorporated into OpenShift release payloads as of August 2026 [4][5][6].
Citations:
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 1138
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 11480
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 2492
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 29653
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 13257
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 1920
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 478
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 2503
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 1041
🏁 Script executed:
Repository: openshift/gcp-filestore-csi-driver
Length of output: 3590
Use a fork release with the
x/net/idnasecurity fix. OSV lists GO-2026-5026 for versions before v0.55.0. The vendored production graph includesgolang.org/x/net/idnathroughgolang.org/x/net/http2, which callsidna.ToASCII. Update the replacement to a fork release with this backport, or use a fixed upstream release.🤖 Prompt for AI Agents
Source: Path instructions