Skip to content

Fix possible fix(deps): golang.org/x/crypto v0.53.0 → 0.55.0 (CVE-2026-56854) in go.mod - #155

Open
begininvoke wants to merge 1 commit into
aenix-io:mainfrom
begininvoke:redgem/security-fix-ab1b06d6
Open

Fix possible fix(deps): golang.org/x/crypto v0.53.0 → 0.55.0 (CVE-2026-56854) in go.mod#155
begininvoke wants to merge 1 commit into
aenix-io:mainfrom
begininvoke:redgem/security-fix-ab1b06d6

Conversation

@begininvoke

Copy link
Copy Markdown

This changes go.mod to address something a scan flagged. It is around line 1.

The vulnerability (CVE‑2026‑56854) is real: the source‑address check in TLS Permissions is only applied to PublicKeyCallback and VerifiedPublicKeyCallback, leaving PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin paths unchecked. An attacker can use those alternative auth methods to bypass source‑address restrictions, potentially allowing connections from unauthorized IPs. This is a critical risk because it undermines network‑level access controls. The fix is to enforce the source‑address check for Permissions returned by all authentication callbacks, which is addressed in golang.org/x/crypto v0.55.0.

Update golang.org/x/crypto to v0.55.0 to fix critical CVE-2026-56854.

For reference: rule CVE-2026-56854. Rated critical.

Take or leave whichever parts are useful. If this is not the right approach, closing is fine.


Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant