Repository navigation
fix: bump Go builder to 1.26.6 and baseline CVE-2026-46600 for oCIS 8.1 - #37
Merged
Merged
Conversation
oCIS 8.1.0 pins golang.org/x/net v0.55.0, which carries CVE-2026-46600 (golang.org/x/net/dns/dnsmessage: DoS via invalid DNS record parsing, fixed in 0.56.0). This is baked into the released 8.1.0 binary and cannot be fixed from this repo — it needs an upstream owncloud/ocis release. The 8.0.7 and 8.2.0 lines already ship v0.57.0 and are clean. This unblocks the pending Go toolchain bump (#36, golang 1.26.5 -> 1.26.6), which is required to clear the eight HIGH stdlib CVEs that have been failing the nightly Docker Rolling Trivy scan since 2026-08-14. With 1.26.6 the only remaining finding across the whole matrix was this 8.1.0 x/net CVE. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Signed-off-by: Thomas Müller <1005065+DeepDiver1975@users.noreply.github.com>
The Go builder was pinned to golang:1.26.5-alpine3.23. Go 1.26.6 fixed eight HIGH severity CVEs, so every ocis binary we build reports them against stdlib v1.26.5 and Trivy fails the scan: CVE-2026-33818 encoding/asn1: DoS via excessive recursion in Unmarshal CVE-2026-39821 golang.org/x/net/idna: privilege escalation via Punycode CVE-2026-46600 golang.org/x/net/dns/dnsmessage: DoS via invalid records CVE-2026-56853 net/http: unencrypted HTTP/2 connections DoS CVE-2026-56858 html/template: XSS via pathological input CVE-2026-56859 encoding/xml: DoS via decoding recursion depth CVE-2026-56860 net/url: DoS from quadratic complexity in path handling CVE-2026-56862 crypto/tls: DoS via indefinite KeyUpdate messages This has failed the nightly Docker Rolling build every night since 2026-08-14 (2 CVEs at first, 8 once the Trivy DB caught up) and the weekly Docker CI release build on 2026-08-16. Digest resolved from docker.io/library/golang:1.26.6-alpine3.23. Supersedes the Renovate PR #36, which made the same bump but could not go green without the 8.1 Trivy baseline entry in the preceding commit. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Signed-off-by: Thomas Müller <1005065+DeepDiver1975@users.noreply.github.com>
2403905
approved these changes
Aug 17, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the nightly Docker Rolling Trivy failure (run 31989688905) and the weekly Docker CI release build failure.
Root cause
v8/Dockerfile.multiarchpinned the Go builder togolang:1.26.5-alpine3.23. Go 1.26.6 fixed 8 HIGH CVEs, so everyocisbinary we build reports them againststdlib v1.26.5and Trivy exits 1:encoding/asn1— DoS via excessive recursion inUnmarshalgolang.org/x/net/idna— privilege escalation via Punycode label processinggolang.org/x/net/dns/dnsmessage— DoS via invalid DNS record parsingnet/http— unencrypted HTTP/2 connections vulnerable to DoShtml/template— XSS via pathological inputencoding/xml— DoS via decoding recursion depthnet/url— DoS from quadratic complexity in path handlingcrypto/tls— DoS via indefiniteKeyUpdatemessagesAll eight list
1.26.6as a fixed version. The failure started on 2026-08-14 with 2 CVEs and grew to 8 by 2026-08-16 as the Trivy DB caught up — no repo change was involved, which is why previously-green builds started failing on their own.Why the Renovate bump (#36) alone wasn't enough
#36 makes the identical Go bump, and it demonstrably fixes the rolling build: the Docker Rolling workflow ran on #36's branch on 2026-08-13 and 2026-08-16 and passed on both arches, while every scheduled master run since 2026-08-14 failed.
But #36's release matrix had one genuine failure left —
build (8.1.0) / build (arm64). Every other job in that run wascancelledby fail-fast, and8.0.7 / arm64passed outright. The remaining finding is a module-level CVE, not stdlib:golang.org/x/netper oCIS ref:golang.org/x/netOnly the 8.1 line is affected. It is baked into the released 8.1.0 binary and cannot be fixed from this repo — it needs an upstream owncloud/ocis release. That is exactly what
v8/8.1/.trivyignoreis for.The two changes have to land together: the Go bump alone leaves 8.1.0 red, and the baseline entry alone leaves all three releases red on the stdlib CVEs.
Changes
v8/8.1/.trivyignore: addCVE-2026-46600 exp:2026-10-31, following the existing entries' format and expiry convention.v8/Dockerfile.multiarch:golang:1.26.5-alpine3.23→1.26.6-alpine3.23(digestsha256:e57c41c1...).Supersedes #36, which can be closed once this merges.
🤖 Generated with Claude Code