Skip to content

fix: upgrade vulnerable Go dependencies to fix CRITICAL/HIGH CVEs - #237

Closed
qiluo-msft wants to merge 1 commit into
masterfrom
fix/cve-go-deps-2026-08
Closed

fix: upgrade vulnerable Go dependencies to fix CRITICAL/HIGH CVEs#237
qiluo-msft wants to merge 1 commit into
masterfrom
fix/cve-go-deps-2026-08

Conversation

@qiluo-msft

@qiluo-msft qiluo-msft commented Aug 6, 2026

Copy link
Copy Markdown

Why I did it

Trivy CVE scan identified multiple CRITICAL and HIGH severity vulnerabilities in the Go module dependencies of sonic-mgmt-common.

How I did it

Updated go.mod with the following version bumps:

Package Old New CVEs Fixed
google.golang.org/grpc v1.28.0 v1.82.1 CVE-2026-33186, GHSA-hrxh-6v49-42gf
golang.org/x/text v0.3.3 v0.39.0 CVE-2020-14040, CVE-2021-38561, CVE-2022-32149, CVE-2026-56852
github.com/antchfx/xpath v1.1.10 v1.3.6 CVE-2026-32287 (direct dependency)
github.com/antchfx/jsonquery v1.1.4 v1.3.7 (parent of vulnerable xpath)
github.com/antchfx/xmlquery v1.3.1 v1.5.1 (parent of vulnerable xpath)

How to verify it

trivy fs . --severity CRITICAL,HIGH

CRITICAL count should drop to 0 for these packages; HIGH count should decrease substantially.

- google.golang.org/grpc v1.28.0 -> v1.82.1 (CVE-2026-33186, GHSA-hrxh-6v49-42gf)
- golang.org/x/text v0.3.3 -> v0.39.0 (CVE-2020-14040, CVE-2021-38561, CVE-2026-56852)
- antchfx/xpath v1.1.10 -> v1.3.6 (CVE-2026-32287, direct dependency)
- antchfx/jsonquery v1.1.4 -> v1.3.7 (parent of vulnerable xpath)
- antchfx/xmlquery v1.3.1 -> v1.5.1 (parent of vulnerable xpath)

Signed-off-by: qiluo <qiluo@microsoft.com>
Copilot AI lite review requested due to automatic review settings August 6, 2026 23:34
@mssonicbld

Copy link
Copy Markdown

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request updates Go module dependency versions in sonic-mgmt-common to remediate CRITICAL/HIGH vulnerabilities reported by Trivy, focusing on gRPC, golang.org/x/text, and the antchfx/* query/xpath stack.

Changes:

  • Bumped google.golang.org/grpc from v1.28.0 to v1.82.1.
  • Bumped golang.org/x/text from v0.3.3 to v0.39.0.
  • Bumped github.com/antchfx/{jsonquery,xmlquery,xpath} to newer patched versions.
Suppressed comments (1)

go.mod:21

  • go.sum does not include checksums for golang.org/x/text v0.39.0 and google.golang.org/grpc v1.82.1 (it still lists v0.3.3 and v1.28.0). Please regenerate module metadata (go mod tidy) and commit the updated go.sum (and any indirect version bumps) so builds don’t depend on local module cache state.
	golang.org/x/text v0.39.0
	google.golang.org/grpc v1.82.1

Comment thread go.mod
Comment on lines +5 to +7
github.com/antchfx/jsonquery v1.3.7
github.com/antchfx/xmlquery v1.5.1
github.com/antchfx/xpath v1.3.6
@qiluo-msft

Copy link
Copy Markdown
Author

Superseded by a new PR with go.sum properly updated via go mod tidy.

@qiluo-msft qiluo-msft closed this Aug 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants