Skip to content

fix: upgrade x/crypto for CVE-2026-56854 and goldmark for GO-2026-5320 - #20

Merged
b404dev merged 1 commit into
mainfrom
fix/cve-2026-56854
Sep 4, 2026
Merged

b404dev merged 1 commit into
mainfrom
fix/cve-2026-56854

Conversation

@b404dev

@b404dev b404dev commented Sep 4, 2026

Copy link
Copy Markdown
Owner

Summary

CVE-2026-56854 / GO-2026-6303 in golang.org/x/crypto/ssh: source-address restrictions returned by password, keyboard-interactive, no-client-auth, and GSSAPI callbacks were not enforced. Fixed upstream in v0.55.0. Abduction pulls x/crypto v0.53.0 transitively through Wails' dev server (labstack/echo → x/crypto/acme) and never calls ssh.NewServerConn; govulncheck confirms no reachable path. Bumped to v0.55.0 so scanners stop flagging the module. x/net, x/sys, and x/text moved to their matching minors.

GO-2026-5320 in github.com/yuin/goldmark: while scanning, govulncheck reported this XSS in link, image, and autolink rendering as reachable from backend/code.go (renderMarkdown). Rendered HTML is already sanitised before display, so exposure was mitigated, but the dependency is now on v1.7.17 where it is fixed.

Verification

  • go build ./..., go vet ./... pass.
  • Markdown and code rendering tests pass against the new goldmark.
  • govulncheck ./... reports no vulnerabilities after the bump.

golang.org/x/crypto v0.53.0 -> v0.55.0 closes CVE-2026-56854 (GO-2026-6303),
a source-address enforcement gap in the SSH server's authentication
callbacks. Abduction never calls ssh.NewServerConn; the module arrives through
Wails' dev server dependency, so this clears the advisory rather than a
reachable path.

github.com/yuin/goldmark v1.7.4 -> v1.7.17 closes GO-2026-5320, an XSS in
link, image, and autolink rendering that govulncheck reports as reachable from
the Markdown reader. Output was already sanitised before display.
@b404dev
b404dev merged commit 92844d5 into main Sep 4, 2026
1 check passed
@b404dev
b404dev deleted the fix/cve-2026-56854 branch September 4, 2026 14:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant