Skip to content

fix: upgrade golang.org/x/crypto to v0.52.0 (12 ssh CVEs)#25780

Merged
f0ssel merged 1 commit into
release/2.32from
sshelnutt/release-2.32-xcrypto-v0.52.0
May 30, 2026
Merged

fix: upgrade golang.org/x/crypto to v0.52.0 (12 ssh CVEs)#25780
f0ssel merged 1 commit into
release/2.32from
sshelnutt/release-2.32-xcrypto-v0.52.0

Conversation

@Shelnutt2

Copy link
Copy Markdown
Contributor

Upgrades golang.org/x/crypto from v0.50.0 to v0.52.0 on release/2.32 to address 12 CVEs in x/crypto/ssh and x/crypto/ssh/agent.

Linear: ENT-90

Changes

  • golang.org/x/crypto v0.50.0 -> v0.52.0
  • golang.org/x/net v0.53.0 -> v0.54.0
  • golang.org/x/sys v0.43.0 -> v0.45.0
  • golang.org/x/term v0.42.0 -> v0.43.0
  • golang.org/x/text v0.36.0 -> v0.37.0
CVEs addressed
CVE Package Severity
CVE-2026-39827 x/crypto/ssh Low
CVE-2026-39828 x/crypto/ssh Low
CVE-2026-39829 x/crypto/ssh Low
CVE-2026-39830 x/crypto/ssh Low
CVE-2026-39831 x/crypto/ssh Low
CVE-2026-39834 x/crypto/ssh Low
CVE-2026-39835 x/crypto/ssh Low
CVE-2026-46595 x/crypto/ssh Low
CVE-2026-46597 x/crypto/ssh Low
CVE-2026-39832 x/crypto/ssh/agent Low
CVE-2026-39833 x/crypto/ssh/agent Low
CVE-2026-46598 x/crypto/ssh/agent Low

Generated by Coder Agents on behalf of @Shelnutt2

Upgrades golang.org/x/crypto from v0.50.0 to v0.52.0 on release/2.32
to address 12 CVEs in x/crypto/ssh and x/crypto/ssh/agent.

See: ENT-90, ENT-88

Transitive dependency updates:
- golang.org/x/net v0.53.0 -> v0.54.0
- golang.org/x/sys v0.43.0 -> v0.45.0
- golang.org/x/term v0.42.0 -> v0.43.0
- golang.org/x/text v0.36.0 -> v0.37.0
@Shelnutt2 Shelnutt2 changed the title fix(deps): upgrade golang.org/x/crypto to v0.52.0 (12 ssh CVEs) fix: upgrade golang.org/x/crypto to v0.52.0 (12 ssh CVEs) May 28, 2026
@Shelnutt2 Shelnutt2 requested a review from f0ssel May 28, 2026 10:17
@Shelnutt2 Shelnutt2 added dependencies Pull requests that update a dependency file cherry-pick/v2.32 labels May 28, 2026
@f0ssel f0ssel merged commit ad37de5 into release/2.32 May 30, 2026
40 of 42 checks passed
@f0ssel f0ssel deleted the sshelnutt/release-2.32-xcrypto-v0.52.0 branch May 30, 2026 19:14
@github-actions github-actions Bot locked and limited conversation to collaborators May 30, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

cherry-pick/v2.32 dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants