Skip to content

fix: upgrade vulnerable Go dependencies to fix CRITICAL/HIGH CVEs - #238

Closed
qiluo-msft wants to merge 2 commits into
masterfrom
fix/cve-mgmt-common-2026-08
Closed

fix: upgrade vulnerable Go dependencies to fix CRITICAL/HIGH CVEs#238
qiluo-msft wants to merge 2 commits into
masterfrom
fix/cve-mgmt-common-2026-08

Conversation

@qiluo-msft

Copy link
Copy Markdown

Why I did it

Trivy CVE scan identified multiple CRITICAL and HIGH severity vulnerabilities in the Go module dependencies of sonic-mgmt-common.

How I did it

Updated go.mod and ran go mod tidy to regenerate go.sum with the following version bumps:

Package Old New CVEs Fixed
google.golang.org/grpc v1.28.0 v1.82.1 CVE-2026-33186, GHSA-hrxh-6v49-42gf
golang.org/x/text v0.3.3 v0.39.0 CVE-2020-14040, CVE-2021-38561, CVE-2022-32149, CVE-2026-56852
github.com/antchfx/xpath v1.1.10 v1.3.6 CVE-2026-32287 (direct dependency)
github.com/antchfx/jsonquery v1.1.4 v1.3.7 (parent of vulnerable xpath)
github.com/antchfx/xmlquery v1.3.1 v1.5.1 (parent of vulnerable xpath)

How to verify it

trivy fs . --severity CRITICAL,HIGH

CRITICAL count should drop to 0 for these packages; HIGH count should decrease substantially.

- google.golang.org/grpc v1.28.0 -> v1.82.1 (CVE-2026-33186, GHSA-hrxh-6v49-42gf)
- golang.org/x/text v0.3.3 -> v0.39.0 (CVE-2020-14040, CVE-2021-38561, CVE-2026-56852)
- antchfx/xpath v1.1.10 -> v1.3.6 (CVE-2026-32287, direct dependency)
- antchfx/jsonquery v1.1.4 -> v1.3.7 (parent of vulnerable xpath)
- antchfx/xmlquery v1.3.1 -> v1.5.1 (parent of vulnerable xpath)

Signed-off-by: qiluo <qiluo@microsoft.com>
Copilot AI lite review requested due to automatic review settings August 6, 2026 23:46
@mssonicbld

Copy link
Copy Markdown

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates this repo’s Go module dependencies to address reported CRITICAL/HIGH CVEs in core libraries used by translib/cvl and related tooling.

Changes:

  • Bumped google.golang.org/grpc to v1.82.1 and golang.org/x/text to v0.39.0, plus related dependency updates in go.mod.
  • Updated antchfx JSON/XML/XPath modules to newer releases and refreshed go.sum accordingly.
  • Bumped the module go directive to 1.25.0 (not mentioned in the PR description).

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.

File Description
go.mod Updates direct/indirect dependency versions (incl. grpc/x/text) and raises the go directive.
go.sum Regenerates dependency checksums to match the new module graph.

Comment thread go.mod
)

go 1.24.4
go 1.25.0
@qiluo-msft

Copy link
Copy Markdown
Author

Superseded by updated PR with rebase on latest master.

@qiluo-msft qiluo-msft closed this Aug 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants