Skip to content

fix(deps): vuln minor: github.com/aws/aws-sdk-go-v2/service/s3, github.com/go-git/go-git/v5, github.com/nats-io/nats-server/v2 [test/new-e2e]#50534

Draft
gh-worker-campaigns-3e9aa4[bot] wants to merge 29 commits into
mainfrom
engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042
Draft

fix(deps): vuln minor: github.com/aws/aws-sdk-go-v2/service/s3, github.com/go-git/go-git/v5, github.com/nats-io/nats-server/v2 [test/new-e2e]#50534
gh-worker-campaigns-3e9aa4[bot] wants to merge 29 commits into
mainfrom
engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor

Summary: High-severity security update — 3 packages upgraded (MINOR changes included)

Manifests changed:

  • test/new-e2e (go)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
github.com/nats-io/nats-server/v2 v2.11.1 v2.14.0 minor Transitive 18 HIGH, 18 MODERATE, 6 MEDIUM
github.com/go-git/go-git/v5 v5.16.5 v5.19.0 minor Transitive 2 MODERATE, 2 MEDIUM, 3 LOW
github.com/aws/aws-sdk-go-v2/service/s3 v1.97.2 v1.101.0 minor Direct 1 MODERATE

Security Details

🚨 Critical & High Severity (18 fixed)
Package CVE Severity Summary Unsafe Version Fixed In
github.com/nats-io/nats-server/v2 GO-2026-4837 high NATS has pre-auth server panic via leafnode handling in github.com/nats-io/nats-server v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 GHSA-52jh-2xxh-pwh6 HIGH NATS Server panic via malicious compression on leafnode port v2.11.1 2.11.14
github.com/nats-io/nats-server/v2 GHSA-v722-jcv5-w7mc HIGH NATS has MQTT plaintext password disclosure v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 GHSA-vprv-35vv-q339 HIGH NATS has pre-auth server panic via leafnode handling v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 CVE-2026-33217 high NATS allows MQTT clients to bypass ACL checks v2.11.1 -
github.com/nats-io/nats-server/v2 CVE-2026-33218 high NATS has pre-auth server panic via leafnode handling v2.11.1 -
github.com/nats-io/nats-server/v2 GO-2026-4834 high NATS allows MQTT clients to bypass ACL checks in github.com/nats-io/nats-server v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 CVE-2026-29785 HIGH NATS Server panic via malicious compression on leafnode port v2.11.1 -
github.com/nats-io/nats-server/v2 GO-2026-4829 HIGH NATS Server panic via malicious compression on leafnode port in github.com/nats-io/nats-server v2.11.1 2.11.14
github.com/nats-io/nats-server/v2 GO-2026-4836 high NATS has MQTT plaintext password disclosure in github.com/nats-io/nats-server v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 GHSA-jxxm-27vp-c3m5 HIGH NATS allows MQTT clients to bypass ACL checks v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 CVE-2026-33216 high NATS has MQTT plaintext password disclosure v2.11.1 -
github.com/nats-io/nats-server/v2 GO-2026-4827 HIGH NATS credentials are exposed in monitoring port via command-line argv in github.com/nats-io/nats-server v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 GHSA-x6g4-f6q3-fqvv HIGH NATS credentials are exposed in monitoring port via command-line argv v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 GHSA-pq2q-rcw4-3hr6 HIGH NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead v2.11.1 2.11.14
github.com/nats-io/nats-server/v2 CVE-2026-27889 high NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead v2.11.1 -
github.com/nats-io/nats-server/v2 GO-2026-4841 high NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead in github.com/nats-io/nats-server v2.11.1 2.11.14
github.com/nats-io/nats-server/v2 CVE-2026-33247 HIGH NATS credentials are exposed in monitoring port via command-line argv v2.11.1 -
ℹ️ Other Vulnerabilities (32)
Package CVE Severity Summary Unsafe Version Fixed In
github.com/go-git/go-git/v5 GO-2026-4910 medium Maliciously crafted idx file can cause asymmetric memory consumption in github.com/go-git/go-git v5.16.5 5.17.1
github.com/go-git/go-git/v5 CVE-2026-34165 medium go-git: Maliciously crafted idx file can cause asymmetric memory consumption v5.16.5 -
github.com/nats-io/nats-server/v2 GO-2026-4533 medium nats-server websockets are vulnerable to pre-auth memory DoS in github.com/nats-io/nats-server v2.11.1 2.11.12
github.com/nats-io/nats-server/v2 GO-2026-4833 medium NATS is vulnerable to MQTT hijacking via Client ID in github.com/nats-io/nats-server v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 CVE-2026-33215 medium NATS is vulnerable to MQTT hijacking via Client ID v2.11.1 -
github.com/nats-io/nats-server/v2 GO-2026-4832 medium NATS JetStream has an authorization bypass through its Management API in github.com/nats-io/nats-server v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 CVE-2026-33222 medium NATS JetStream has an authorization bypass through its Management API v2.11.1 -
github.com/nats-io/nats-server/v2 CVE-2026-27571 medium nats-server websockets are vulnerable to pre-auth memory DoS v2.11.1 -
github.com/aws/aws-sdk-go-v2/service/s3 GHSA-xmrv-pmrh-hhx2 MODERATE Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder v1.97.2 1.97.3
github.com/go-git/go-git/v5 GHSA-jhf3-xxhw-2wpp MODERATE go-git: Maliciously crafted idx file can cause asymmetric memory consumption v5.16.5 5.17.1
github.com/go-git/go-git/v5 GHSA-3xc5-wrhm-f963 MODERATE go-git: Credential leak via cross-host redirect in smart HTTP transport v5.16.5 5.18.0
github.com/nats-io/nats-server/v2 GO-2026-4830 MODERATE NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers in github.com/nats-io/nats-server v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 CVE-2026-33248 MODERATE NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching v2.11.1 -
github.com/nats-io/nats-server/v2 GO-2026-4828 MODERATE NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching in github.com/nats-io/nats-server v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 GHSA-3f24-pcvm-5jqc MODERATE NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 GO-2026-4835 MODERATE NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing in github.com/nats-io/nats-server v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 GHSA-fcjp-h8cc-6879 MODERATE NATS is vulnerable to MQTT hijacking via Client ID v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 CVE-2026-33223 MODERATE NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing v2.11.1 -
github.com/nats-io/nats-server/v2 GHSA-pwx7-fx9r-hr4h MODERATE NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 GO-2026-4831 MODERATE NATS is vulnerable to pre-auth DoS through WebSockets client service in github.com/nats-io/nats-server v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 CVE-2026-33219 MODERATE NATS is vulnerable to pre-auth DoS through WebSockets client service v2.11.1 -
github.com/nats-io/nats-server/v2 GHSA-8r68-gvr4-jh7j MODERATE NATS is vulnerable to pre-auth DoS through WebSockets client service v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 GHSA-9983-vrx2-fg9c MODERATE NATS JetStream has an authorization bypass through its Management API v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 GHSA-qrvq-68c2-7grw MODERATE nats-server websockets are vulnerable to pre-auth memory DoS v2.11.1 2.11.12
github.com/nats-io/nats-server/v2 GO-2026-4826 MODERATE NATS: Message tracing can be redirected to arbitrary subject in github.com/nats-io/nats-server v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 CVE-2026-33249 MODERATE NATS: Message tracing can be redirected to arbitrary subject v2.11.1 -
github.com/nats-io/nats-server/v2 GHSA-8m2x-3m6q-6w8j MODERATE NATS: Message tracing can be redirected to arbitrary subject v2.11.1 2.11.15
github.com/nats-io/nats-server/v2 CVE-2026-33246 MODERATE NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers v2.11.1 -
github.com/nats-io/nats-server/v2 GHSA-55h8-8g96-x4hj MODERATE NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers v2.11.1 2.11.15
github.com/go-git/go-git/v5 GO-2026-4909 LOW Missing validation decoding Index v4 files leads to panic in github.com/go-git/go-git v5.16.5 5.17.1
github.com/go-git/go-git/v5 CVE-2026-33762 LOW go-git: Missing validation decoding Index v4 files leads to panic v5.16.5 -
github.com/go-git/go-git/v5 GHSA-gm2x-2g9h-ccm8 LOW go-git missing validation decoding Index v4 files leads to panic v5.16.5 5.17.1

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: Vulnerability Remediation (High)

🤖 Generated by DataDog Automated Dependency Management System

@datadog-prod-us1-5

datadog-prod-us1-5 Bot commented May 8, 2026

Copy link
Copy Markdown
Contributor

Pipelines

Fix all issues with BitsAI

⚠️ Warnings

🚦 6 Pipeline jobs failed

DataDog/datadog-agent | go_mod_tidy_check   View in Datadog   GitLab

DataDog/datadog-agent | oracle: [21.3.0-xe]   View in Datadog   GitLab

DataDog/datadog-agent | tests_ebpf_arm64   View in Datadog   GitLab

View all 6 failed jobs.

ℹ️ Info

🎯 Code Coverage (details)
Patch Coverage: 100.00%
Overall Coverage: 50.87% (+0.11%)

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 43f0764 | Docs | Datadog PR Page | Give us feedback!

@dd-octo-sts

dd-octo-sts Bot commented May 8, 2026

Copy link
Copy Markdown
Contributor

Files inventory check summary

File checks results against ancestor f8e962f1:

Results for datadog-agent_7.81.0~devel.git.756.102b71a.pipeline.118322511-1_amd64.deb:

No change detected

@gh-worker-campaigns-3e9aa4

gh-worker-campaigns-3e9aa4 Bot commented May 8, 2026

Copy link
Copy Markdown
Contributor Author

Auto-rebase complete

Branch is up to date with main — rebased onto abc1689.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-03ec73 dd-octo-sts-03ec73 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042 branch from 748d3f3 to 63b43b8 Compare May 8, 2026 19:56
@dd-octo-sts-94e5d1 dd-octo-sts-94e5d1 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042 branch from 63b43b8 to c2f98ff Compare May 12, 2026 13:11
@dd-octo-sts-aad58d dd-octo-sts-aad58d Bot force-pushed the engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042 branch from c2f98ff to 319befc Compare May 13, 2026 00:27
@dd-octo-sts-4caf68 dd-octo-sts-4caf68 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042 branch from 319befc to 9feaead Compare May 13, 2026 08:47
@dd-octo-sts-98cdbc dd-octo-sts-98cdbc Bot force-pushed the engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042 branch from 9feaead to 1e5e6fc Compare May 13, 2026 12:11
@dd-octo-sts-0c48d7 dd-octo-sts-0c48d7 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042 branch from 1e5e6fc to bea6861 Compare May 13, 2026 14:18
@dd-octo-sts-6cbbf8 dd-octo-sts-6cbbf8 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042 branch from bea6861 to 99e133b Compare May 13, 2026 19:00
@dd-octo-sts-dcc400 dd-octo-sts-dcc400 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042 branch from 99e133b to 43a9274 Compare May 14, 2026 04:50
@dd-octo-sts-03ec73 dd-octo-sts-03ec73 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042 branch from 43a9274 to 814925c Compare May 14, 2026 07:50
@dd-octo-sts-b8cf80 dd-octo-sts-b8cf80 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042 branch from 814925c to fd18353 Compare May 14, 2026 12:38
@dd-octo-sts-03ec73 dd-octo-sts-03ec73 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042 branch from fd18353 to 3c4c065 Compare May 14, 2026 22:01
@dd-octo-sts dd-octo-sts Bot force-pushed the engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042 branch from 3c4c065 to a3709f9 Compare May 15, 2026 19:29
@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor Author

Auto-rebase failed

Lockfile regeneration failed during rebase onto main. Your branch was not updated. You may need to rebase and regenerate lockfiles manually.

Error details
  • Go Mod Tidy: ❌ exit status 127
Error Details (up to 4000 chars)
gimme: sha256sum failed for '/tmp/gimme/go1.25.5.linux.amd64.tar.gz'
gimme: continuing to next candidate URL
I don't have any idea what to do with '1.25.5'.
  (using download type 'binary')
bash: line 1: go: command not found

  • Custom Action: registry.ddbuild.io/engraver-custom-action:update-go-mod-dd-source ✅ (0.45s)

  • Custom Action: registry.ddbuild.io/engraver-custom-action:update-go-mod-dd-source ✅ (0.38s)


Auto-Rebase · Add no-auto-rebase to opt out

@gh-worker-campaigns-3e9aa4

gh-worker-campaigns-3e9aa4 Bot commented May 19, 2026

Copy link
Copy Markdown
Contributor Author

Auto-rebase complete

Branch is up to date with main — rebased onto fb06699.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-dcc400 dd-octo-sts-dcc400 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042 branch from a3709f9 to a6b9159 Compare May 19, 2026 10:59
@dd-octo-sts-4caf68 dd-octo-sts-4caf68 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042 branch from a6b9159 to 07e5398 Compare May 19, 2026 18:01
@dd-octo-sts-6cbbf8 dd-octo-sts-6cbbf8 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/go/new-e2e/0-1778213042 branch from 07e5398 to 5569823 Compare May 20, 2026 18:54
dd-octo-sts-0c48d7 Bot and others added 27 commits June 12, 2026 03:40
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-019303[bot] <256648753+dd-octo-sts-019303[bot]@users.noreply.github.com>
@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor Author

Auto-rebase complete

Branch is up to date with main — rebased onto 58d5a5f.


Auto-Rebase · Add no-auto-rebase to opt out

@github-actions

Copy link
Copy Markdown
Contributor

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Already looking forward to the next diff.

Reviewed commit: 43f0764c8d

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants