Skip to content

[v26.1.x] rpk: bump x/net to v0.55.0 (Snyk findings)#30737

Merged
r-vasquez merged 1 commit into
redpanda-data:v26.1.xfrom
vbotbuildovich:backport-pr-30735-v26.1.x-854
Jun 9, 2026
Merged

[v26.1.x] rpk: bump x/net to v0.55.0 (Snyk findings)#30737
r-vasquez merged 1 commit into
redpanda-data:v26.1.xfrom
vbotbuildovich:backport-pr-30735-v26.1.x-854

Conversation

@vbotbuildovich

Copy link
Copy Markdown
Collaborator

Backport of PR #30735

Addresses CVE-2026-39821 (GO-2026-5026), an improper-authentication
issue in golang.org/x/net/idna. Bumps golang.org/x/net v0.54.0 =>
v0.55.0 (and transitive golang.org/x/sys v0.44.0 => v0.45.0) in
src/go/rpk.

govulncheck confirms GO-2026-5026 is no longer reachable after the bump.

Refs:
- https://pkg.go.dev/vuln/GO-2026-5026
- https://nvd.nist.gov/vuln/detail/CVE-2026-39821

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
(cherry picked from commit 1b49719)
@vbotbuildovich vbotbuildovich requested a review from r-vasquez as a code owner June 8, 2026 22:39
@vbotbuildovich vbotbuildovich added this to the v26.1.x-next milestone Jun 8, 2026
@vbotbuildovich vbotbuildovich added the kind/backport PRs targeting a stable branch label Jun 8, 2026
@vbotbuildovich vbotbuildovich requested review from a team and kbatuigas as code owners June 8, 2026 22:39
@vbotbuildovich vbotbuildovich requested a review from twmb June 8, 2026 22:39
@r-vasquez r-vasquez enabled auto-merge June 8, 2026 22:43
@r-vasquez r-vasquez merged commit 187965b into redpanda-data:v26.1.x Jun 9, 2026
23 of 27 checks passed
@tyson-redpanda tyson-redpanda modified the milestones: v26.1.x-next, v26.1.10 Jun 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/rpk kind/backport PRs targeting a stable branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants