Skip to content

fix(deps): vuln minor: github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream, github.com/aws/aws-sdk-go-v2/service/s3, github.com/containerd/containerd/v2 [smoke] - #42

Draft
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/minorpatch/go/smoke/3-1783348117

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: High-severity security update — 3 packages upgraded (MINOR changes included)

Manifests changed:

  • smoke (go)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
github.com/containerd/containerd/v2 v2.1.5 v2.3.2 minor Transitive 8 HIGH, 4 MEDIUM
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.6.3 v1.7.14 minor Transitive 1 MEDIUM
github.com/aws/aws-sdk-go-v2/service/s3 v1.58.2 v1.104.2 minor Transitive 1 MEDIUM

Security Details

🚨 Critical & High Severity (8 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
github.com/containerd/containerd/v2 GO-2026-5064 HIGH containerd CRI checkpoint restore CDI annotation smuggling in github.com/containerd/containerd v2.1.5 2.1.9 -
github.com/containerd/containerd/v2 GHSA-xhf5-7wjv-pqxp HIGH containerd CRI — image-config LABEL flows to restart-monitor binary:// logger: host-root command execution from an image pull v2.1.5 2.0.10 -
github.com/containerd/containerd/v2 GHSA-fqw6-gf59-qr4w HIGH containerd user ID handling bypass allows runAsNonRoot evasion v2.1.5 2.0.9 -
github.com/containerd/containerd/v2 GHSA-rgh6-rfwx-v388 HIGH Arbitrary host CRI log file read via symlink following in CRI checkpoint restore v2.1.5 2.1.9 -
github.com/containerd/containerd/v2 GO-2026-5758 HIGH containerd CRI — image-config LABEL flows to restart-monitor binary:// logger: host-root command execution from an image pull in github.com/containerd/containerd v2.1.5 2.0.10 -
github.com/containerd/containerd/v2 GO-2026-5622 HIGH Arbitrary host CRI log file read via symlink following in CRI checkpoint restore in github.com/containerd/containerd v2.1.5 2.1.9 -
github.com/containerd/containerd/v2 GHSA-33vj-92qq-66hc HIGH containerd CRI checkpoint restore CDI annotation smuggling v2.1.5 2.1.9 -
github.com/containerd/containerd/v2 GO-2026-5378 HIGH containerd user ID handling bypass allows runAsNonRoot evasion in github.com/containerd/containerd v2.1.5 2.0.9 -
ℹ️ Other Vulnerabilities (6)
Package CVE Severity Summary Unsafe Version Fixed In Case
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream GHSA-xmrv-pmrh-hhx2 MODERATE Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder v1.6.3 1.7.8 -
github.com/aws/aws-sdk-go-v2/service/s3 GHSA-xmrv-pmrh-hhx2 MODERATE Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder v1.58.2 1.97.3 -
github.com/containerd/containerd/v2 GO-2026-5475 MODERATE containerd image-triggered runtime DoS via unbounded group parsing in github.com/containerd/containerd v2.1.5 2.0.10 -
github.com/containerd/containerd/v2 GHSA-jpcc-p29g-p8mq MODERATE containerd image-triggered runtime DoS via unbounded group parsing v2.1.5 2.0.10 -
github.com/containerd/containerd/v2 GHSA-cvxm-645q-p574 MODERATE containerd: CRI checkpoint import allows local image tag poisoning v2.1.5 2.1.9 -
github.com/containerd/containerd/v2 GO-2026-5338 MODERATE containerd: CRI checkpoint import allows local image tag poisoning in github.com/containerd/containerd v2.1.5 2.1.9 -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

…am, github.com/aws/aws-sdk-go-v2/service/s3, github.com/containerd/containerd/v2 [smoke]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants