Skip to content

Bump dependencies to fix known vulnerabilities - #371

Merged
mbyczkowski merged 2 commits into
masterfrom
mbyczkowski/bump-vuln-deps
Sep 23, 2026
Merged

mbyczkowski merged 2 commits into
masterfrom
mbyczkowski/bump-vuln-deps

Conversation

@mbyczkowski

@mbyczkowski mbyczkowski commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Why

certigo's go.mod pins 6 modules at versions with 26 published Go vulnerability advisories. govulncheck ./... finds 3 that certigo's own code can reach:

  • GO-2026-5052 (GHSA-mpwr-8vm7-h73f): pkcs12.ToPEM can accept a PKCS#12 file encoded with the wrong password. certigo calls it to read PKCS#12 files (lib/certs.go:365).
  • GO-2026-5970 (CVE-2026-56852): zlint's certificate lints call x/text/unicode/norm, which can loop forever on invalid UTF-8.
  • GO-2026-5026 (CVE-2026-39821): zlint calls idna.ToUnicode, which accepts Punycode labels that decode to plain ASCII.

It finds no call path to the other 23. Scanners that match by version still flag every certigo build that includes them.

What

This bumps 7 modules to newer minor or patch releases. It has no major bumps and needs no newer Go. It also bumps golangci-lint in the Lint job from v2.3.0 to v2.13.2, so Lint passes again.

Module From To Advisories fixed
golang.org/x/crypto v0.47.0 v0.55.0 14
golang.org/x/net (indirect) v0.49.0 v0.58.0 8
golang.org/x/text (indirect) v0.33.0 v0.41.0 1
golang.org/x/sys (indirect) v0.40.0 v0.47.0 1 (Windows only)
golang.org/x/term (indirect) v0.39.0 v0.45.0 0
software.sslmate.com/src/go-pkcs12 v0.7.0 v0.7.3 1
github.com/Azure/go-ntlmssp (indirect) v0.1.0 v0.1.1 1
All 26 advisory IDs
  • golang.org/x/crypto: GO-2026-5005, GO-2026-5006, GO-2026-5013, GO-2026-5014, GO-2026-5015, GO-2026-5016, GO-2026-5017, GO-2026-5018, GO-2026-5019, GO-2026-5020, GO-2026-5021, GO-2026-5023, GO-2026-5033, GO-2026-6303
  • golang.org/x/net: GO-2026-4918, GO-2026-5025, GO-2026-5026, GO-2026-5027, GO-2026-5028, GO-2026-5029, GO-2026-5030, GO-2026-5942
  • golang.org/x/text: GO-2026-5970
  • golang.org/x/sys: GO-2026-5024
  • software.sslmate.com/src/go-pkcs12: GO-2026-5052
  • github.com/Azure/go-ntlmssp: GO-2026-5543

How

  • Each golang.org/x module moves to its newest release that still supports Go 1.25. The next release of each needs Go 1.26.
  • x/crypto v0.55.0 requires x/sys v0.47.0, x/term v0.45.0 and x/text v0.41.0, so those three follow it.
  • The go line in go.mod now reads 1.25.0 instead of 1.25. The new x/ releases declare go 1.25.0, and Go orders 1.25 before 1.25.0, so go get rewrites the line. Both lines mean Go 1.25, and any Go 1.25 release still builds certigo.
  • zcrypto and zlint do not change. They have no advisories, and master holds zcrypto back on purpose for Windows (c30a3d6, e835bb6).
  • The Lint job installs Go stable, which is now 1.27. golangci-lint v2.3.0 cannot load packages compiled by Go 1.27, so Lint failed on any PR, whatever it changed. v2.3.0 fails the same way on master's code. v2.13.2 is the latest release, and it accepts .golangci.yaml as is.

Three advisories remain in govulncheck -scan module. certigo cannot reach any of them:

  • GO-2026-6354 (CVE-2026-78662) and GO-2026-6355 (CVE-2026-56855) are DoS bugs in x/crypto/ssh. Only x/crypto v0.56.0 fixes them, and it needs Go 1.26. certigo does not build x/crypto/ssh. It links only x/crypto/ssh/terminal.
  • GO-2026-5932 marks x/crypto/openpgp as unmaintained. No fixed version exists. certigo does not import it.

Risk

Low. certigo's own code does not change, and every bump is a minor or patch release. One behavior changes: go-pkcs12 v0.7.3 rejects malformed PKCS#12 files that v0.7.0 accepted or crashed on. These are files with a PBMAC1 key length under 20 or over 64 bytes, or a PBES2 IV that does not match the AES block size. certigo now prints an error for them.

Testing

CI builds and tests with Go stable only (1.27 today). These checks cover the rest:

  • govulncheck ./... with GOOS set to darwin, linux and windows: 3 reachable advisories before, 0 after.
  • govulncheck -scan module: 29 advisories before, 3 after (listed above).
  • GOTOOLCHAIN=go1.25.5 go vet ./... and GOTOOLCHAIN=go1.25.5 go test ./... pass.
  • All 17 cram tests pass against a go1.25.5 build: PATH=<dir with go1.25.5 certigo>:$PATH cram tests/*.t.
  • CGO_ENABLED=0 builds with go1.25.5 pass for all 5 release targets: darwin/amd64, darwin/arm64, linux/amd64, linux/arm64 and windows/amd64. The compile check job builds amd64 only.

Bigger picture

Generated with Claude Code

@mbyczkowski
mbyczkowski marked this pull request as ready for review September 23, 2026 17:26
@mbyczkowski
mbyczkowski requested a review from a team as a code owner September 23, 2026 17:26
@mbyczkowski
mbyczkowski merged commit d93339f into master Sep 23, 2026
25 checks passed
@mbyczkowski
mbyczkowski deleted the mbyczkowski/bump-vuln-deps branch September 23, 2026 17:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants