fix(marketplace): clear CVE-2026-34182 + Critical/High CVEs (openssl + Go) - #3
Merged
SongHyeopPark merged 2 commits intoJul 2, 2026
Merged
Conversation
The published marketplace image (alpine:3.23) ships libcrypto3/libssl3 3.5.6-r0, which grype flags as CVE-2026-34182 (OpenSSL CMS AuthEnvelopedData input-validation bypass, CVSS 9.1 Critical), fixed in openssl 3.5.7-r0. The same 3.5.7-r0 bump also clears the sibling openssl CVEs present in the image (CVE-2026-34180/34181/34183, 42764, 45445, 45447, 7383, 9076). Pin the runtime libs to >=3.5.7-r0 so the fix lands regardless of any cached base-image layer. Verified on alpine:3.23 that the constraint resolves to libcrypto3/libssl3-3.5.7-r0. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
euphoria0-0
approved these changes
Jul 2, 2026
Rebuild the marketplace image with a patched Go toolchain and updated module dependencies to clear the Go-ecosystem CVEs baked into the minio binary (these can't be fixed via apk since they compile into the binary). Builder: golang:1.25.9-alpine -> golang:1.26.4-alpine (clears 25 stdlib CVEs; newest fix required go1.26.4). go.mod toolchain bumped to match. Module bumps (grype fix versions): golang.org/x/crypto 0.37.0 -> 0.52.0 (3 Critical + 9 High, incl. SSH/FIDO) google.golang.org/grpc 1.72.0 -> 1.79.3 (Critical: :path authz bypass) golang.org/x/net 0.39.0 -> 0.55.0 golang.org/x/sys 0.32.0 -> 0.45.0 go.opentelemetry.io/otel/sdk 1.35.0 -> 1.43.0 github.com/prometheus/prometheus 0.303.0 -> 0.311.3 github.com/apache/thrift 0.21.0 -> 0.23.0 github.com/go-jose/go-jose/v4 4.1.0 -> 4.1.4 github.com/buger/jsonparser 1.1.1 -> 1.1.2 go.mongodb.org/mongo-driver 1.17.3 -> 1.17.7 github.com/eclipse/paho.mqtt.golang 1.5.0 -> 1.5.1 github.com/Azure/go-ntlmssp 2022... -> 0.1.1 filippo.io/edwards25519 1.1.0 -> 1.1.1 Verified: `go build -mod=readonly` (Docker default) compiles cleanly, and a grype scan of the rebuilt image drops from 100 findings (6 Critical / 49 High) to 3 (all Medium, no fix available: busybox CVE-2025-60876). CVE-2026-34182 and all Critical/High Go CVEs are gone. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Remediate the CVEs in the published marketplace minio image
gcr.io/cloud-marketplace/heaan-public/envector-sm/minio@sha256:fb3bc18…on two fronts:libcrypto3/libssl3>=3.5.7-r0inDockerfile.marketplace.golang:1.26.4-alpineand bumpedgo.moddeps — these CVEs are compiled into the minio binary and can't be patched viaapk.Why
grype on the published image (alpine 3.23.4, built with go1.25.9) reported 100 findings — 6 Critical / 49 High. Root causes:
3.5.7-r0.golang.org/x/cryptov0.37.0 → 3 Critical (SSH >4GB write DoS, FIDO/U2F user-presence bypass, keyringConfirmBeforeUsenot enforced) + 9 High → 0.52.0.google.golang.org/grpcv1.72.0 → Critical:pathauthz bypass (CVE-2026-33186) → 1.79.3.Changes
Dockerfile.marketplace: buildergolang:1.25.9-alpine→golang:1.26.4-alpine; runtime pinslibcrypto3>=3.5.7-r0/libssl3>=3.5.7-r0.go.mod/go.sum: toolchaingo1.25.9→go1.26.4; security module bumps (x/crypto 0.52.0, grpc 1.79.3, x/net 0.55.0, x/sys 0.45.0, otel/sdk 1.43.0, prometheus 0.311.3, thrift 0.23.0, go-jose 4.1.4, jsonparser 1.1.2, mongo-driver 1.17.7, paho.mqtt 1.5.1, go-ntlmssp 0.1.1, edwards25519 1.1.1).Verification
go build -mod=readonly(Docker default mode) compiles cleanly with all bumps.Dockerfile.marketplaceand re-scanned with grype:The 3 remaining findings are all Medium
CVE-2025-60876in busybox (busybox/busybox-binsh/ssl_client1.37.0-r30) — no fixed version exists upstream, inherited from the alpine base, out of our control.Note
minio is a pure-Go binary (
CGO_ENABLED=0) and does not link system openssl, and several x/crypto Criticals are in SSH/FIDO code paths outside minio's object-storage surface — so real exploitability is low, but these still fail SBOM/grype CVE gates, so the rebuild is required to pass CI and Marketplace scans.🤖 Generated with Claude Code