Skip to content

fix: upgrade golang.org/x/crypto to v0.52.0 (release/2.29)#25779

Merged
f0ssel merged 1 commit into
release/2.29from
seth/ent-95-ironbank-v229x-upgrade-xcrypto-to-v0520-12-ssh-cves
May 30, 2026
Merged

fix: upgrade golang.org/x/crypto to v0.52.0 (release/2.29)#25779
f0ssel merged 1 commit into
release/2.29from
seth/ent-95-ironbank-v229x-upgrade-xcrypto-to-v0520-12-ssh-cves

Conversation

@Shelnutt2

Copy link
Copy Markdown
Contributor

Upgrades golang.org/x/crypto from v0.50.0 to v0.52.0 on the release/2.29 branch to address 12 x/crypto/ssh CVEs.

Fixes ENT-95

Changes

  • golang.org/x/crypto v0.50.0 -> v0.52.0
  • golang.org/x/net v0.53.0 -> v0.54.0 (transitive)
  • golang.org/x/sys v0.43.0 -> v0.45.0 (transitive)
  • golang.org/x/term v0.42.0 -> v0.43.0 (transitive)
  • golang.org/x/text v0.36.0 -> v0.37.0 (transitive)
CVEs addressed
CVE Package Severity
CVE-2026-39827 x/crypto/ssh Low
CVE-2026-39828 x/crypto/ssh Low
CVE-2026-39829 x/crypto/ssh Low
CVE-2026-39830 x/crypto/ssh Low
CVE-2026-39831 x/crypto/ssh Low
CVE-2026-39834 x/crypto/ssh Low
CVE-2026-39835 x/crypto/ssh Low
CVE-2026-46595 x/crypto/ssh Low
CVE-2026-46597 x/crypto/ssh Low
CVE-2026-39832 x/crypto/ssh/agent Low
CVE-2026-39833 x/crypto/ssh/agent Low
CVE-2026-46598 x/crypto/ssh/agent Low

Generated by Coder Agents on behalf of @Shelnutt2. ENT-95

Addresses 12 x/crypto/ssh CVEs affecting v0.50.0 on the release/2.29 branch.
See ENT-88 for the full CVE list.

Also upgrades transitive x/ dependencies:
- x/net v0.53.0 -> v0.54.0
- x/sys v0.43.0 -> v0.45.0
- x/term v0.42.0 -> v0.43.0
- x/text v0.36.0 -> v0.37.0
@Shelnutt2 Shelnutt2 requested a review from f0ssel May 28, 2026 10:17
@Shelnutt2 Shelnutt2 changed the title fix(go.mod): upgrade golang.org/x/crypto to v0.52.0 (release/2.29) fix: upgrade golang.org/x/crypto to v0.52.0 (release/2.29) May 28, 2026
@Shelnutt2 Shelnutt2 added dependencies Pull requests that update a dependency file cherry-pick/v2.29 Needs to be cherry-picked to the 2.29 release branch labels May 28, 2026
@f0ssel f0ssel merged commit 0940955 into release/2.29 May 30, 2026
37 of 39 checks passed
@f0ssel f0ssel deleted the seth/ent-95-ironbank-v229x-upgrade-xcrypto-to-v0520-12-ssh-cves branch May 30, 2026 19:54
@github-actions github-actions Bot locked and limited conversation to collaborators May 30, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

cherry-pick/v2.29 Needs to be cherry-picked to the 2.29 release branch dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants