Skip to content

Bump google.golang.org/grpc to >=1.82.1 (GHSA-hrxh-6v49-42gf, High 8.8) #2586

Description

@advallespir

Summary

The google.golang.org/grpc dependency (currently v1.81.1) is affected by GHSA-hrxh-6v49-42gf (CVSS 4.0: 8.8, High), covering three issues in the xDS RBAC engine and the HTTP/2 transport:

  • Authorization bypass (fail-open) when Metadata or RequestedServerName matchers appear in an xDS RBAC policy
  • HTTP/2 Rapid Reset mitigation bypass, enabling a high-CPU denial of service
  • Server panic when parsing crafted xDS RBAC policies with NOT rules on unsupported fields

Fixed in v1.82.1.

Detected via an AWS Inspector scan of a FrankenPHP-based image.

Could you bump to >=1.82.1? It may already land in the next release, but flagging in case it helps prioritize.

Thanks

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions