Skip to content

all: bump google.golang.org/grpc to v1.83.2 to address CVE-2026-84304 - #1812

Merged
RafalKorepta merged 1 commit into
mainfrom
rk/snyk-grpc-bump
Sep 3, 2026
Merged

all: bump google.golang.org/grpc to v1.83.2 to address CVE-2026-84304#1812
RafalKorepta merged 1 commit into
mainfrom
rk/snyk-grpc-bump

Conversation

@RafalKorepta

Copy link
Copy Markdown
Contributor

Description

Bumps google.golang.org/grpc from v1.82.1 to v1.83.2 in every workspace module that carries the dependency, and tidies the full workspace.

Vulnerability

Allocation of Resources Without Limits or Throttling in google.golang.org/grpc v1.82.1, reported against the internal/envconfig, internal/mem, internal/transport, and mem packages (HIGH severity).

Snyk currently reports "no fix available" for these findings; that is database lag — the fix is published upstream (grpc-go ≥ v1.83.1). Bumped to the latest release, v1.83.2.

Backport PRs to release/v26.2.x, release/v26.1.x, and release/v25.3.x follow separately.

🤖 Generated with Claude Code

@secpanda

secpanda commented Sep 3, 2026

Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Addresses CVE-2026-84304 (GHSA-vp52-pcj8-j9qc): Allocation of Resources
Without Limits or Throttling in google.golang.org/grpc v1.82.1, reported
by Snyk against the internal/envconfig, internal/mem, internal/transport,
and mem packages. Bumped in every workspace module that carries the
dependency and tidied the full workspace.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@RafalKorepta
RafalKorepta enabled auto-merge (rebase) September 3, 2026 13:50
@RafalKorepta
RafalKorepta merged commit fb905ff into main Sep 3, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants