Skip to content

fix(marketplace): clear CVE-2026-34182 + Critical/High CVEs (openssl + Go) - #3

Merged
SongHyeopPark merged 2 commits into
release/2025-10-15-go1.25.9from
fix/openssl-cve-2026-34182
Jul 2, 2026
Merged

SongHyeopPark merged 2 commits into
release/2025-10-15-go1.25.9from
fix/openssl-cve-2026-34182

Conversation

@SongHyeopPark

@SongHyeopPark SongHyeopPark commented Jul 2, 2026 •

Copy link
Copy Markdown
Contributor

What

Remediate the CVEs in the published marketplace minio image
gcr.io/cloud-marketplace/heaan-public/envector-sm/minio@sha256:fb3bc18… on two fronts:

  1. OS package (openssl): pin libcrypto3/libssl3 >=3.5.7-r0 in Dockerfile.marketplace.
  2. Go binary (toolchain + modules): rebuild with golang:1.26.4-alpine and bumped go.mod deps — these CVEs are compiled into the minio binary and can't be patched via apk.

Why

grype on the published image (alpine 3.23.4, built with go1.25.9) reported 100 findings — 6 Critical / 49 High. Root causes:

  • openssl 3.5.6-r0 → CVE-2026-34182 (CMS AuthEnvelopedData bypass, CVSS 9.1) + 8 sibling openssl CVEs, all fixed in 3.5.7-r0.
  • Go stdlib go1.25.9 → 25 CVEs (newest fix requires go1.26.4).
  • golang.org/x/crypto v0.37.0 → 3 Critical (SSH >4GB write DoS, FIDO/U2F user-presence bypass, keyring ConfirmBeforeUse not enforced) + 9 High → 0.52.0.
  • google.golang.org/grpc v1.72.0 → Critical :path authz bypass (CVE-2026-33186) → 1.79.3.
  • plus x/net, otel, prometheus, thrift, go-jose, jsonparser, mongo-driver, etc.

Changes

  • Dockerfile.marketplace: builder golang:1.25.9-alpine → golang:1.26.4-alpine; runtime pins libcrypto3>=3.5.7-r0 / libssl3>=3.5.7-r0.
  • go.mod / go.sum: toolchain go1.25.9 → go1.26.4; security module bumps (x/crypto 0.52.0, grpc 1.79.3, x/net 0.55.0, x/sys 0.45.0, otel/sdk 1.43.0, prometheus 0.311.3, thrift 0.23.0, go-jose 4.1.4, jsonparser 1.1.2, mongo-driver 1.17.7, paho.mqtt 1.5.1, go-ntlmssp 0.1.1, edwards25519 1.1.1).

Verification

  • go build -mod=readonly (Docker default mode) compiles cleanly with all bumps.
  • Rebuilt the image locally from Dockerfile.marketplace and re-scanned with grype:
Original image This PR
Total 100 3
Critical 6 0
High 49 0
Medium 39 3
CVE-2026-34182 ❌ present ✅ gone
openssl 3.5.6-r0 3.5.7-r0

The 3 remaining findings are all Medium CVE-2025-60876 in busybox (busybox/busybox-binsh/ssl_client 1.37.0-r30) — no fixed version exists upstream, inherited from the alpine base, out of our control.

Note

minio is a pure-Go binary (CGO_ENABLED=0) and does not link system openssl, and several x/crypto Criticals are in SSH/FIDO code paths outside minio's object-storage surface — so real exploitability is low, but these still fail SBOM/grype CVE gates, so the rebuild is required to pass CI and Marketplace scans.

🤖 Generated with Claude Code

The published marketplace image (alpine:3.23) ships libcrypto3/libssl3
3.5.6-r0, which grype flags as CVE-2026-34182 (OpenSSL CMS AuthEnvelopedData
input-validation bypass, CVSS 9.1 Critical), fixed in openssl 3.5.7-r0.
The same 3.5.7-r0 bump also clears the sibling openssl CVEs present in the
image (CVE-2026-34180/34181/34183, 42764, 45445, 45447, 7383, 9076).

Pin the runtime libs to >=3.5.7-r0 so the fix lands regardless of any cached
base-image layer. Verified on alpine:3.23 that the constraint resolves to
libcrypto3/libssl3-3.5.7-r0.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@SongHyeopPark
SongHyeopPark requested a review from inkme9 July 2, 2026 06:33
Rebuild the marketplace image with a patched Go toolchain and updated
module dependencies to clear the Go-ecosystem CVEs baked into the minio
binary (these can't be fixed via apk since they compile into the binary).

Builder: golang:1.25.9-alpine -> golang:1.26.4-alpine (clears 25 stdlib CVEs;
newest fix required go1.26.4). go.mod toolchain bumped to match.

Module bumps (grype fix versions):
  golang.org/x/crypto        0.37.0 -> 0.52.0   (3 Critical + 9 High, incl. SSH/FIDO)
  google.golang.org/grpc     1.72.0 -> 1.79.3   (Critical: :path authz bypass)
  golang.org/x/net           0.39.0 -> 0.55.0
  golang.org/x/sys           0.32.0 -> 0.45.0
  go.opentelemetry.io/otel/sdk 1.35.0 -> 1.43.0
  github.com/prometheus/prometheus 0.303.0 -> 0.311.3
  github.com/apache/thrift   0.21.0 -> 0.23.0
  github.com/go-jose/go-jose/v4 4.1.0 -> 4.1.4
  github.com/buger/jsonparser 1.1.1 -> 1.1.2
  go.mongodb.org/mongo-driver 1.17.3 -> 1.17.7
  github.com/eclipse/paho.mqtt.golang 1.5.0 -> 1.5.1
  github.com/Azure/go-ntlmssp 2022... -> 0.1.1
  filippo.io/edwards25519    1.1.0 -> 1.1.1

Verified: `go build -mod=readonly` (Docker default) compiles cleanly, and a
grype scan of the rebuilt image drops from 100 findings (6 Critical / 49 High)
to 3 (all Medium, no fix available: busybox CVE-2025-60876). CVE-2026-34182
and all Critical/High Go CVEs are gone.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@SongHyeopPark SongHyeopPark changed the title fix(marketplace): pin openssl >=3.5.7-r0 to clear CVE-2026-34182 fix(marketplace): clear CVE-2026-34182 + Critical/High CVEs (openssl + Go) Jul 2, 2026
@SongHyeopPark
SongHyeopPark merged commit 80cd189 into release/2025-10-15-go1.25.9 Jul 2, 2026
1 check passed
@SongHyeopPark
SongHyeopPark deleted the fix/openssl-cve-2026-34182 branch July 2, 2026 06:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants