Summary
The google.golang.org/grpc dependency (currently v1.81.1) is affected by GHSA-hrxh-6v49-42gf (CVSS 4.0: 8.8, High), covering three issues in the xDS RBAC engine and the HTTP/2 transport:
- Authorization bypass (fail-open) when Metadata or RequestedServerName matchers appear in an xDS RBAC policy
- HTTP/2 Rapid Reset mitigation bypass, enabling a high-CPU denial of service
- Server panic when parsing crafted xDS RBAC policies with NOT rules on unsupported fields
Fixed in v1.82.1.
Detected via an AWS Inspector scan of a FrankenPHP-based image.
Could you bump to >=1.82.1? It may already land in the next release, but flagging in case it helps prioritize.
Thanks
Summary
The google.golang.org/grpc dependency (currently v1.81.1) is affected by GHSA-hrxh-6v49-42gf (CVSS 4.0: 8.8, High), covering three issues in the xDS RBAC engine and the HTTP/2 transport:
Fixed in v1.82.1.
Detected via an AWS Inspector scan of a FrankenPHP-based image.
Could you bump to >=1.82.1? It may already land in the next release, but flagging in case it helps prioritize.
Thanks