Skip to content

Fix(ci): bump grpc to v1.84.0 to resolve newly disclosed CVEs - #3869

Merged
prkalle merged 2 commits into
cloudfoundry:v8from
prkalle:fix/grpc-cve-v8
Sep 24, 2026
Merged

prkalle merged 2 commits into
cloudfoundry:v8from
prkalle:fix/grpc-cve-v8

Conversation

@prkalle

@prkalle prkalle commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Description of the Change

This PR bumps grpc dependency to v1.84.0 to resolve (and supress the false positive CVE since it is already fixed in grpc v1.84.0) newly disclosed CVEs and fix the CVE check CI.

Why Is This PR Valuable?

This PR resolves the CVEs

Applicable Issues

List any applicable GitHub Issues here

How Urgent Is The Change?

Fairly urgent

grpc-go v1.82.1 (fixed here previously for an older CVE) has since had
three new CVEs disclosed against it: CVE-2026-84445 and CVE-2026-84304
(High), CVE-2026-84303 (Medium).

Signed-off-by: Prem Kumar Kalle <prem.kalle@broadcom.com>
grpc v1.84.0 (bumped in the previous commit) already contains this
fix -- grpc-go's own advisory lists v1.82.2 and v1.83.2 as fixed
releases, both older than v1.84.0, and the actual v1.84.0 source
already has the :authority header check from the fix commit. The
scanner DB anchors "fixed in" to an unreleased dev pseudo-version from
a squash-merged backport, so it can't recognize the later tagged
release supersedes it, and keeps flagging it as a false positive.

Signed-off-by: Prem Kumar Kalle <prem.kalle@broadcom.com>
@prkalle
prkalle merged commit 06b0ff8 into cloudfoundry:v8 Sep 24, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants