Skip to content

fix: bump Go builder to 1.26.6 and baseline CVE-2026-46600 for oCIS 8.1 - #37

Merged
DeepDiver1975 merged 2 commits into
masterfrom
fix/trivy-8.1-x-net-cve
Aug 17, 2026
Merged

DeepDiver1975 merged 2 commits into
masterfrom
fix/trivy-8.1-x-net-cve

Conversation

@DeepDiver1975

@DeepDiver1975 DeepDiver1975 commented Aug 17, 2026 •

Copy link
Copy Markdown
Contributor

Fixes the nightly Docker Rolling Trivy failure (run 31989688905) and the weekly Docker CI release build failure.

Root cause

v8/Dockerfile.multiarch pinned the Go builder to golang:1.26.5-alpine3.23. Go 1.26.6 fixed 8 HIGH CVEs, so every ocis binary we build reports them against stdlib v1.26.5 and Trivy exits 1:

CVE Package
CVE-2026-33818 encoding/asn1 — DoS via excessive recursion in Unmarshal
CVE-2026-39821 golang.org/x/net/idna — privilege escalation via Punycode label processing
CVE-2026-46600 golang.org/x/net/dns/dnsmessage — DoS via invalid DNS record parsing
CVE-2026-56853 net/http — unencrypted HTTP/2 connections vulnerable to DoS
CVE-2026-56858 html/template — XSS via pathological input
CVE-2026-56859 encoding/xml — DoS via decoding recursion depth
CVE-2026-56860 net/url — DoS from quadratic complexity in path handling
CVE-2026-56862 crypto/tls — DoS via indefinite KeyUpdate messages

All eight list 1.26.6 as a fixed version. The failure started on 2026-08-14 with 2 CVEs and grew to 8 by 2026-08-16 as the Trivy DB caught up — no repo change was involved, which is why previously-green builds started failing on their own.

Why the Renovate bump (#36) alone wasn't enough

#36 makes the identical Go bump, and it demonstrably fixes the rolling build: the Docker Rolling workflow ran on #36's branch on 2026-08-13 and 2026-08-16 and passed on both arches, while every scheduled master run since 2026-08-14 failed.

But #36's release matrix had one genuine failure left — build (8.1.0) / build (arm64). Every other job in that run was cancelled by fail-fast, and 8.0.7 / arm64 passed outright. The remaining finding is a module-level CVE, not stdlib:

| golang.org/x/net | CVE-2026-46600 | HIGH | fixed | v0.55.0 | 0.56.0 |

golang.org/x/net per oCIS ref:

ref golang.org/x/net affected
v8.0.7 v0.57.0 no
v8.1.0 v0.55.0 yes
v8.2.0 v0.57.0 no
master (rolling) v0.58.0 no

Only the 8.1 line is affected. It is baked into the released 8.1.0 binary and cannot be fixed from this repo — it needs an upstream owncloud/ocis release. That is exactly what v8/8.1/.trivyignore is for.

The two changes have to land together: the Go bump alone leaves 8.1.0 red, and the baseline entry alone leaves all three releases red on the stdlib CVEs.

Changes

  • v8/8.1/.trivyignore: add CVE-2026-46600 exp:2026-10-31, following the existing entries' format and expiry convention.
  • v8/Dockerfile.multiarch: golang:1.26.5-alpine3.23 → 1.26.6-alpine3.23 (digest sha256:e57c41c1...).

Supersedes #36, which can be closed once this merges.

🤖 Generated with Claude Code

DeepDiver1975 and others added 2 commits August 17, 2026 11:56
oCIS 8.1.0 pins golang.org/x/net v0.55.0, which carries CVE-2026-46600
(golang.org/x/net/dns/dnsmessage: DoS via invalid DNS record parsing,
fixed in 0.56.0). This is baked into the released 8.1.0 binary and
cannot be fixed from this repo — it needs an upstream owncloud/ocis
release. The 8.0.7 and 8.2.0 lines already ship v0.57.0 and are clean.

This unblocks the pending Go toolchain bump (#36, golang 1.26.5 ->
1.26.6), which is required to clear the eight HIGH stdlib CVEs that
have been failing the nightly Docker Rolling Trivy scan since
2026-08-14. With 1.26.6 the only remaining finding across the whole
matrix was this 8.1.0 x/net CVE.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Thomas Müller <1005065+DeepDiver1975@users.noreply.github.com>
The Go builder was pinned to golang:1.26.5-alpine3.23. Go 1.26.6 fixed
eight HIGH severity CVEs, so every ocis binary we build reports them
against stdlib v1.26.5 and Trivy fails the scan:

  CVE-2026-33818  encoding/asn1: DoS via excessive recursion in Unmarshal
  CVE-2026-39821  golang.org/x/net/idna: privilege escalation via Punycode
  CVE-2026-46600  golang.org/x/net/dns/dnsmessage: DoS via invalid records
  CVE-2026-56853  net/http: unencrypted HTTP/2 connections DoS
  CVE-2026-56858  html/template: XSS via pathological input
  CVE-2026-56859  encoding/xml: DoS via decoding recursion depth
  CVE-2026-56860  net/url: DoS from quadratic complexity in path handling
  CVE-2026-56862  crypto/tls: DoS via indefinite KeyUpdate messages

This has failed the nightly Docker Rolling build every night since
2026-08-14 (2 CVEs at first, 8 once the Trivy DB caught up) and the
weekly Docker CI release build on 2026-08-16.

Digest resolved from docker.io/library/golang:1.26.6-alpine3.23.
Supersedes the Renovate PR #36, which made the same bump but could not
go green without the 8.1 Trivy baseline entry in the preceding commit.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Thomas Müller <1005065+DeepDiver1975@users.noreply.github.com>
@DeepDiver1975 DeepDiver1975 changed the title fix: ignore CVE-2026-46600 in the oCIS 8.1 Trivy baseline fix: bump Go builder to 1.26.6 and baseline CVE-2026-46600 for oCIS 8.1 Aug 17, 2026
@DeepDiver1975
DeepDiver1975 merged commit 71a2ea3 into master Aug 17, 2026
18 checks passed
@DeepDiver1975
DeepDiver1975 deleted the fix/trivy-8.1-x-net-cve branch August 17, 2026 10:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants