Skip to content

fix(deps): bump google.golang.org/grpc to v1.83.2 - #310

Merged
adamdecaf merged 1 commit into
masterfrom
security/grpc-1.83.2
Sep 2, 2026
Merged

adamdecaf merged 1 commit into
masterfrom
security/grpc-1.83.2

Conversation

@adamdecaf

Copy link
Copy Markdown
Member

🤖 This PR was opened by a robot.

Bumps google.golang.org/grpc from v1.83.0 to v1.83.2 to address CVE-2026-84304 (gRPC-Go OOM via HTTP/2 DATA frame fragmentation).

Also bumps golang.org/x/crypto from v0.54.0 to v0.55.0 for CVE-2026-56854 (SSH source-address bypass). golang.org/x/net was pulled to v0.58.0 as a transitive update.

Fixes https://github.com/moov-io/irs/security/dependabot/74

CVE-2026-84304 / GHSA-vp52-pcj8-j9qc: gRPC-Go OOM via HTTP/2
DATA frame fragmentation. Also bump golang.org/x/crypto to
v0.55.0 (CVE-2026-56854).

Fixes https://github.com/moov-io/irs/security/dependabot/74
@adamdecaf
adamdecaf merged commit eeafad6 into master Sep 2, 2026
7 checks passed
@adamdecaf
adamdecaf deleted the security/grpc-1.83.2 branch September 2, 2026 14:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant