Skip to content

DFBUGS-6102: [release-4.20] [CVE-2026-33186]: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation#410

Merged
openshift-merge-bot[bot] merged 1 commit intored-hat-storage:release-4.20from
iPraveenParihar:backport-4.20/cve-2026-33186
Apr 8, 2026
Merged

DFBUGS-6102: [release-4.20] [CVE-2026-33186]: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation#410
openshift-merge-bot[bot] merged 1 commit intored-hat-storage:release-4.20from
iPraveenParihar:backport-4.20/cve-2026-33186

Conversation

@iPraveenParihar
Copy link
Copy Markdown
Member

Bumps the golang-dependencies group with 1 update:
google.golang.org/grpc.

Updates google.golang.org/grpc from 1.73.0 to 1.79.3


CVE fixed in previous releases
4.22: e009c1f
4.21: bf6e461


GHSA-p77j-4mvh-x3m3

Bumps the golang-dependencies group with 1 update:
[google.golang.org/grpc](https://github.com/grpc/grpc-go).

Updates `google.golang.org/grpc` from 1.73.0 to 1.79.3

Signed-off-by: Praveen M <m.praveen@ibm.com>
@openshift-ci-robot openshift-ci-robot added jira/severity-important Referenced Jira bug's severity is important for the branch this PR is targeting. jira/valid-reference jira/invalid-bug labels Apr 6, 2026
@openshift-ci-robot
Copy link
Copy Markdown

openshift-ci-robot commented Apr 6, 2026

@iPraveenParihar: This pull request references [Jira Issue DFBUGS-6102](https://redhat.atlassian.net/browse/DFBUGS-6102), which is invalid:

  • expected the vulnerability to target the "odf-4.20.10" version, but no target version was set

Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.

Details

In response to this:

Bumps the golang-dependencies group with 1 update:
google.golang.org/grpc.

Updates google.golang.org/grpc from 1.73.0 to 1.79.3


CVE fixed in previous releases
4.22: e009c1f
4.21: bf6e461


GHSA-p77j-4mvh-x3m3

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci openshift-ci Bot added the approved label Apr 6, 2026
@iPraveenParihar iPraveenParihar marked this pull request as ready for review April 6, 2026 14:58
@iPraveenParihar iPraveenParihar changed the title DFBUGS-6102: [release-4.21] [CVE-2026-33186]: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation DFBUGS-6102: [release-4.20] [CVE-2026-33186]: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation Apr 7, 2026
@iPraveenParihar
Copy link
Copy Markdown
Member Author

/jira refresh

@openshift-ci-robot
Copy link
Copy Markdown

openshift-ci-robot commented Apr 8, 2026

@iPraveenParihar: This pull request references [Jira Issue DFBUGS-6102](https://redhat.atlassian.net/browse/DFBUGS-6102), which is invalid:

  • expected the vulnerability to target the "odf-4.20.10" version, but no target version was set

Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.

Details

In response to this:

/jira refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@black-dragon74
Copy link
Copy Markdown
Member

/lgtm

@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented Apr 8, 2026

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: black-dragon74, iPraveenParihar

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:
  • OWNERS [black-dragon74,iPraveenParihar]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@iPraveenParihar
Copy link
Copy Markdown
Member Author

/jira refresh

@openshift-ci-robot openshift-ci-robot added jira/valid-bug Indicates that the referenced jira bug is valid for the branch this PR is targeting and removed jira/invalid-bug labels Apr 8, 2026
@openshift-ci-robot
Copy link
Copy Markdown

openshift-ci-robot commented Apr 8, 2026

@iPraveenParihar: This pull request references [Jira Issue DFBUGS-6102](https://redhat.atlassian.net/browse/DFBUGS-6102), which is valid. The bug has been moved to the POST state.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (odf-4.20.10) matches configured target version for branch (odf-4.20.10)
  • bug is in the state ASSIGNED, which is one of the valid states (NEW, ASSIGNED, POST)
Details

In response to this:

/jira refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-merge-bot openshift-merge-bot Bot merged commit 4d07005 into red-hat-storage:release-4.20 Apr 8, 2026
12 of 13 checks passed
@openshift-ci-robot
Copy link
Copy Markdown

openshift-ci-robot commented Apr 8, 2026

@iPraveenParihar: [Jira Issue DFBUGS-6102](https://redhat.atlassian.net/browse/DFBUGS-6102): All pull requests linked via external trackers have merged:

[Jira Issue DFBUGS-6102](https://redhat.atlassian.net/browse/DFBUGS-6102) has been moved to the MODIFIED state.

Details

In response to this:

Bumps the golang-dependencies group with 1 update:
google.golang.org/grpc.

Updates google.golang.org/grpc from 1.73.0 to 1.79.3


CVE fixed in previous releases
4.22: e009c1f
4.21: bf6e461


GHSA-p77j-4mvh-x3m3

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved jira/severity-important Referenced Jira bug's severity is important for the branch this PR is targeting. jira/valid-bug Indicates that the referenced jira bug is valid for the branch this PR is targeting jira/valid-reference lgtm

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants