Skip to content

fix: build with Go 1.27.2 to fix stdlib DoS CVEs - #405

Closed
log0u7 wants to merge 2 commits into
powerman:mainfrom
log0u7:fix/go-toolchain-1.27.2
Closed

log0u7 wants to merge 2 commits into
powerman:mainfrom
log0u7:fix/go-toolchain-1.27.2

Conversation

@log0u7

@log0u7 log0u7 commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Releases are built with the toolchain from go.mod (your shared powerman/workflows build.yml uses actions/setup-go with go-version-file: 'go.mod'), so v0.25.2 shipped with Go 1.26.6, whose stdlib is affected by three HIGH DoS issues fixed in 1.26.9/1.27.2:

  • CVE-2026-78667 - net/http: DoS via crafted HTTP Range headers
  • CVE-2026-78669 - net/http/internal/http2: DoS via excessive HTTP/2 SETTINGS
  • CVE-2026-97031 - crypto/tls: DoS via multiple ECH outer extension references

This PR bumps the go directive to 1.27.2 so the next release embeds the fixed stdlib. One-line change.

Context: Closes #406 - we scan the foreman-proxy container images (which embed dockerize) with Trivy at --exit-code 1 on HIGH, so release binaries built from the vulnerable stdlib keep failing our scans.

Releases are built with the toolchain from go.mod (go-version-file).
go1.26.6 binaries are affected by the net/http and crypto/tls DoS issues
CVE-2026-78667, CVE-2026-78669, CVE-2026-97031 (fixed in 1.26.9/1.27.2).
@log0u7
log0u7 requested a review from powerman as a code owner October 10, 2026 20:31
@log0u7 log0u7 changed the title Build with Go 1.27.2 (stdlib DoS CVE-2026-78667/78669/97031) fix: build with Go 1.27.2 to fix stdlib DoS CVEs Oct 10, 2026
powerman
powerman previously approved these changes Oct 10, 2026
…1.27.2

The CI lint toolchain (mise.lock golangci-lint built with go1.26) rejects
a go.mod targeting 1.27.2. GOTOOLCHAIN=auto picks up the toolchain
directive for builds and tests, and setup-go (go-version-file) honors
the toolchain directive for releases, so release binaries still embed
the fixed stdlib: CVE-2026-78667, CVE-2026-78669, CVE-2026-97031.
@powerman

Copy link
Copy Markdown
Owner

Thanks for the heads-up. It looks like you didn't checked "allow edits by maintainers", so I had to replace this PR with #407 to update linter to fix CI issue.

@powerman powerman closed this Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Release binaries embed Go 1.26.6 stdlib with known DoS CVEs (CVE-2026-78667, CVE-2026-78669, CVE-2026-97031)

2 participants