Skip to content

chore: address CVE CVE-2026-33186#1300

Merged
britaniar merged 1 commit intoAzure:mainfrom
britaniar:fixCVE
Apr 28, 2026
Merged

chore: address CVE CVE-2026-33186#1300
britaniar merged 1 commit intoAzure:mainfrom
britaniar:fixCVE

Conversation

@britaniar
Copy link
Copy Markdown
Contributor

@britaniar britaniar commented Apr 28, 2026

Description of your changes

Fixes #

I have: address CVE found https://github.com/Azure/fleet/actions/runs/24688527474/job/72204124181

  • Run make reviewable to ensure this PR is ready for review.

How has this code been tested

Special notes for your reviewer

hubagent (gobinary)

Total: 1 (HIGH: 0, CRITICAL: 1)

┌────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────┬─────────────────────────────────────────────────────────────┐
│ Library │ Vulnerability │ Severity │ Status │ Installed Version │ Fixed Version │ Title │
├────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼───────────────┼─────────────────────────────────────────────────────────────┤
│ google.golang.org/grpc │ CVE-2026-33186 │ CRITICAL │ fixed │ v1.72.1 │ 1.79.3 │ google.golang.org/grpc/grpc-go: │
│ │ │ │ │ │ │ google.golang.org/grpc/authz: gRPC-Go: Authorization bypass │
│ │ │ │ │ │ │ due to improper HTTP/2 path validation │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-33186
└────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────┴─────────────────────────────────────────────────────────────┘

Only present on Azure/fleet repo since this dependency is only used here for the capacity feature.

Signed-off-by: Britania Rodriguez Reyes <britaniar@microsoft.com>
@britaniar britaniar merged commit ece0d07 into Azure:main Apr 28, 2026
25 of 27 checks passed
@britaniar britaniar deleted the fixCVE branch April 28, 2026 22:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants