Skip to content

CVE-2026-22184: bump GRPC lib.#619

Closed
ami-descope wants to merge 1 commit intoVictoriaMetrics:mainfrom
ami-descope:CVE-2026-22184
Closed

CVE-2026-22184: bump GRPC lib.#619
ami-descope wants to merge 1 commit intoVictoriaMetrics:mainfrom
ami-descope:CVE-2026-22184

Conversation

@ami-descope
Copy link
Copy Markdown
Contributor

@ami-descope ami-descope commented Apr 6, 2026

Related issue: #616

Describe Your Changes

Bump GRPC

Checklist

The following checks are mandatory:


Summary by cubic

Updates google.golang.org/grpc from v1.78.0 to v1.79.0 to remediate CVE-2026-22184 and apply the latest security fix. Addresses #616; dependency files only, no functional code changes.

Written for commit e0d3b1f. Summary will update on new commits.

Copy link
Copy Markdown
Contributor

@cubic-dev-ai cubic-dev-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

@ami-descope
Copy link
Copy Markdown
Contributor Author

@arturminchukov can you please review?

@arturminchukov arturminchukov self-assigned this Apr 16, 2026
@arturminchukov
Copy link
Copy Markdown
Member

@ami-descope
in the issue you mentioned that the fixed version is 1.79.3, but in PR you bumped the version to 1.79.0.
Also need to run go mod vendor to synchronize vendor directory with the go.mod
can you sign you commit please?

@arturminchukov
Copy link
Copy Markdown
Member

@ami-descope this vulnerability was fixed in this commit during fixing other Go vulnerabilities.
So I'm closing this pr. Thanks for contributing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants