Skip to content

fix(cve): CVE-2026-33811, CVE-2026-39833 - update Go stdlib and x/crypto [release-v0.37.x] - #2923

Merged
tekton-robot merged 1 commit into
release-v0.37.xfrom
fix/SRVKP-12558-SRVKP-12570-cve-2026-33811-cve-2026-39833-release-v0.37.6-attempt-1
Jul 13, 2026
Merged

tekton-robot merged 1 commit into
release-v0.37.xfrom
fix/SRVKP-12558-SRVKP-12570-cve-2026-33811-cve-2026-39833-release-v0.37.6-attempt-1

Conversation

@divyansh42

Copy link
Copy Markdown
Member

CVE Details

CVE Severity Description Fix
CVE-2026-33811 Undefined Go net package: Denial of Service via long CNAME response in LookupCNAME Go stdlib 1.25.9 → 1.25.11
CVE-2026-39833 Undefined golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation x/crypto v0.46.0 → v0.52.0

Fix Summary

  • Updated Go stdlib directive in go.mod: go 1.25.9 → go 1.25.11
  • Updated golang.org/x/crypto: v0.46.0 → v0.52.0 (minimum safe patch in same minor line per advisory)
  • Ran go mod tidy && go mod verify && go mod vendor — all passed ✅
  • Transitive upgrades: x/net v0.48.0→v0.54.0, x/sync v0.19.0→v0.20.0, x/sys v0.42.0→v0.45.0, x/term v0.41.0→v0.43.0, x/text v0.32.0→v0.37.0

Test Results

✅ Tests PASSED — go test -mod=vendor ./...

All packages passed. Full suite including pkg/cmd/pipelinerun and pkg/cmd/taskrun.

Breaking Changes

None expected. This is a pure dependency version bump. The x/crypto update stays within the same major version (v0). stdlib bump is patch-level only.

Risk Assessment

Low — Patch-level updates only. All unit tests pass. No API surface changes in updated packages relevant to tkn CLI usage.

Jira References

SRVKP-12558, SRVKP-12570

Verification Steps

  • govulncheck scan shows CVE-2026-33811 and CVE-2026-39833 resolved
  • go test -mod=vendor ./... passes
  • go mod verify shows all modules verified
  • No regressions in CLI behavior

🤖 Generated with Claude Code

@tekton-robot tekton-robot added the do-not-merge/release-note-label-needed Indicates that a PR should not merge because it's missing one of the release note labels. label Jun 24, 2026
@tekton-robot tekton-robot added the size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. label Jun 24, 2026
@divyansh42 divyansh42 changed the title fix(cve): CVE-2026-33811, CVE-2026-39833 - update Go stdlib and x/crypto [pipelines-1.15] fix(cve): CVE-2026-33811, CVE-2026-39833 - update Go stdlib and x/crypto [release-v0.37.6] Jul 2, 2026
@divyansh42 divyansh42 added the release-note-none Denotes a PR that doesnt merit a release note. label Jul 2, 2026
@tekton-robot tekton-robot removed the do-not-merge/release-note-label-needed Indicates that a PR should not merge because it's missing one of the release note labels. label Jul 2, 2026
@divyansh42

Copy link
Copy Markdown
Member Author

/retest

@divyansh42
divyansh42 force-pushed the fix/SRVKP-12558-SRVKP-12570-cve-2026-33811-cve-2026-39833-release-v0.37.6-attempt-1 branch from 2776328 to 0aabf3c Compare July 3, 2026 08:00
@divyansh42
divyansh42 changed the base branch from release-v0.37.6 to release-v0.37.x July 3, 2026 12:48
@divyansh42

Copy link
Copy Markdown
Member Author

/hold
PR need to be rebased

@tekton-robot tekton-robot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Jul 6, 2026
@divyansh42
divyansh42 force-pushed the fix/SRVKP-12558-SRVKP-12570-cve-2026-33811-cve-2026-39833-release-v0.37.6-attempt-1 branch from 0aabf3c to cf45832 Compare July 9, 2026 09:19
@divyansh42 divyansh42 changed the title fix(cve): CVE-2026-33811, CVE-2026-39833 - update Go stdlib and x/crypto [release-v0.37.6] fix(cve): CVE-2026-33811, CVE-2026-39833 - update Go stdlib and x/crypto [release-v0.37.x] Jul 9, 2026
@divyansh42
divyansh42 force-pushed the fix/SRVKP-12558-SRVKP-12570-cve-2026-33811-cve-2026-39833-release-v0.37.6-attempt-1 branch 3 times, most recently from 3e33e39 to dfbe2f2 Compare July 10, 2026 09:49
@tekton-robot tekton-robot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Jul 10, 2026
- Update Go stdlib from 1.25.9 to 1.25.11
  Addresses CVE-2026-33811 (DoS via long CNAME response in net.LookupCNAME)
- Update golang.org/x/crypto from v0.46.0 to v0.52.0
  Addresses CVE-2026-39833 (security bypass in ssh/agent key confirmation)
- Also upgrades transitive deps: x/net, x/sync, x/sys, x/term, x/text

Resolves: SRVKP-12558, SRVKP-12570

Co-Assisted-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Divyanshu Agrawal <diagrawa@redhat.com>
@divyansh42
divyansh42 force-pushed the fix/SRVKP-12558-SRVKP-12570-cve-2026-33811-cve-2026-39833-release-v0.37.6-attempt-1 branch from dfbe2f2 to 597ee95 Compare July 13, 2026 03:50
@tekton-robot tekton-robot added size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. and removed needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. labels Jul 13, 2026
@pratap0007

Copy link
Copy Markdown
Contributor

/lgtm
/approve

@tekton-robot tekton-robot added the lgtm Indicates that a PR is ready to be merged. label Jul 13, 2026
@tekton-robot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: pratap0007

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@tekton-robot tekton-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 13, 2026
@divyansh42

Copy link
Copy Markdown
Member Author

/hold cancel

@tekton-robot tekton-robot removed the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Jul 13, 2026
@tekton-robot
tekton-robot merged commit 81bf76a into release-v0.37.x Jul 13, 2026
19 of 21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. release-note-none Denotes a PR that doesnt merit a release note. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants