Skip to content

Fix possible fix(deps): 22 vulnerable dependencies in go.mod - #214

Closed
begininvoke wants to merge 1 commit into
dodevops:developfrom
begininvoke:redgem/security-fix-cec5c6e1
Closed

Fix possible fix(deps): 22 vulnerable dependencies in go.mod#214
begininvoke wants to merge 1 commit into
dodevops:developfrom
begininvoke:redgem/security-fix-cec5c6e1

Conversation

@begininvoke

Copy link
Copy Markdown

Proposing a fix for something flagged in go.mod. It is around line 1.

CRITICAL: CVE-2026-56854 affects golang.org/x/crypto v0.45.0 (ssh package). The SSH server failed to enforce the source-address critical option (Permissions.CriticalOptions['source-address']) for authentication granted via PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin. Only the PublicKeyCallback paths validated it. Impact: any application that restricts SSH access by source IP through these callback types has that restriction silently ignored, allowing clients to authenticate from unauthorized/attacker-controlled networks — an effective authentication bypass of IP allowlisting. Because this weakens a primary access-control mechanism for SSH servers, the severity is correctly rated CRITICAL and should be remediated immediately. Risk level: Critical. Fix: upgrade golang.org/x/crypto to v0.55.0, which applies the source-address check to Permissions returned by any authentication callback.

Updates vulnerable transitive dependencies to fixed versions as per the security advisory.

For reference: rule CVE-2026-56854. Rated critical.

Take or leave whichever parts are useful. If this is not the right approach, closing is fine.


Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.

@begininvoke
begininvoke requested a review from a team as a code owner September 10, 2026 01:19
@dploeger

Copy link
Copy Markdown
Member

Duplicated

@dploeger dploeger closed this Sep 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants