Repository navigation
deps: bump google.golang.org/grpc v1.82.2 for CVE-2026-84445 - #81
Conversation
Fix gRPC-Go Denial of Service via malformed RPC requests (CVSS 7.5). Servers using xds.NewGRPCServer() could panic on an RPC missing the :authority and Host headers, terminating the server process. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: baijum The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
🤖 Finished Review · ✅ Success · Started 5:15 AM UTC · Completed 5:25 AM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $2.71 |
|
Review skipped — this PR is already merged. The Posted by fullsend pre-review check |
|
🤖 Finished Retro · ✅ Success · Started 5:15 AM UTC · Completed 5:26 AM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $2.62 |
|
Review skipped — this PR is already merged. The Posted by fullsend post-review check |
Retro: PR #81 — deps: bump grpc v1.82.2 for CVE-2026-84445Timeline
ObservationsThis is a straightforward vendored dependency bump fixing CVE-2026-84445 (gRPC-Go DoS, CVSS 7.5). PR #81 is the same fix as PR #78 but targeting No novel proposals are warranted. All improvement opportunities identified are already tracked in existing open issues:
What went well
Agents repoDiscovered from run 36387333268 logs: |
Summary
google.golang.org/grpcfrom v1.82.1 to v1.82.2 to fix CVE-2026-84445xds.NewGRPCServer()could panic on an RPC missing the:authorityandHostheaders, terminating the entire server processJira: HELM-857 / OCPTOOLS-2684
Changes
Only the gRPC dependency bump — no changes to go directive, Kubernetes API versions, or any other dependencies.
🤖 Generated with Claude Code