Skip to content

Fix possible fix(deps): 17 vulnerable dependencies in go.mod - #387

Closed
begininvoke wants to merge 1 commit into
please-build:masterfrom
begininvoke:redgem/security-fix-d4e93f7d
Closed

Fix possible fix(deps): 17 vulnerable dependencies in go.mod#387
begininvoke wants to merge 1 commit into
please-build:masterfrom
begininvoke:redgem/security-fix-d4e93f7d

Conversation

@begininvoke

Copy link
Copy Markdown

Proposing a fix for something flagged in go.mod. It is around line 1.

The source‑address restriction in Permissions returned by authentication callbacks was incomplete. Only PublicKeyCallback and VerifiedPublicKeyCallback validated the client's remote address, leaving PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback and GSSAPIWithMICConfig.AllowLogin callbacks ignoring the restriction. An attacker could bypass address‑based authentication controls, leading to unauthorized access. This is a critical issue as it effectively nullifies a core security control of the SSH server. Upgrading to golang.org/x/crypto v0.55.0 includes a fix that applies the source‑address check to all authentication callbacks, closing the gap.

Updates vulnerable dependencies to their fixed versions as reported by Trivy.

For reference: rule CVE-2026-56854. Rated critical.

Take or leave whichever parts are useful. If this is not the right approach, closing is fine.


Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.

@toastwaffle

Copy link
Copy Markdown
Contributor

This is missing corresponding updates to go.sum (which should be relevant to any Go repository). This also requires some changes specific to our build system, so this is superseded by #389

@toastwaffle toastwaffle closed this Sep 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants