Skip to content

Fix possible fix(deps): 22 vulnerable dependencies in go.mod - #213

Closed
begininvoke wants to merge 1 commit into
dodevops:developfrom
begininvoke:redgem/security-fix-2962c02c
Closed

Fix possible fix(deps): 22 vulnerable dependencies in go.mod#213
begininvoke wants to merge 1 commit into
dodevops:developfrom
begininvoke:redgem/security-fix-2962c02c

Conversation

@begininvoke

Copy link
Copy Markdown

Proposing a fix for something flagged in go.mod. It is around line 1.

CRITICAL: CVE-2026-56854 affects golang.org/x/crypto v0.45.0 (ssh package). The SSH server failed to enforce the source-address critical option (Permissions.CriticalOptions['source-address']) for authentication granted via PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin. Only the PublicKeyCallback paths validated it. Impact: any application that restricts SSH access by source IP through these callback types has that restriction silently ignored, allowing clients to authenticate from unauthorized/attacker-controlled networks — an effective authentication bypass of IP allowlisting. Because this weakens a primary access-control mechanism for SSH servers, the severity is correctly rated CRITICAL and should be remediated immediately. Risk level: Critical. Fix: upgrade golang.org/x/crypto to v0.55.0, which applies the source-address check to Permissions returned by any authentication callback.

Updates indirect dependencies in go.mod to patched versions, addressing the reported CVEs. No functional changes are introduced beyond the security fixes.

For reference: rule CVE-2026-56854. Rated critical.

Take or leave whichever parts are useful. If this is not the right approach, closing is fine.


Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.

@begininvoke
begininvoke requested a review from a team as a code owner September 10, 2026 01:18
@dploeger

Copy link
Copy Markdown
Member

We're relying on Dependabot rather than LLM based contributions here and have already dismissed this change.

@dploeger dploeger closed this Sep 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants