diff --git a/.grype.yaml b/.grype.yaml index 38517d7af5..26fec99bdd 100644 --- a/.grype.yaml +++ b/.grype.yaml @@ -27,6 +27,17 @@ ignore: package: name: google.golang.org/grpc version: v1.82.1 + # CVE-2026-84445 is the same temporary exception documented in .trivyignore.yaml: + # Trivy 0.74.0 still embeds grpc 1.82.1, while the 1.82.2 / 1.83.2 fix is not in any + # release. The panic needs a gRPC server built with `xds.NewGRPCServer()`; Prowler only + # runs `trivy image` / `trivy fs`, so the image serves no gRPC at all. Pinned to the + # embedded version so the rule stops matching on its own once Trivy bumps grpc. Remove + # with the Trivy exception by 2026-10-15. + # https://github.com/advisories/GHSA-2v4p-qf9q-27wj + - vulnerability: CVE-2026-84445 + package: + name: google.golang.org/grpc + version: v1.82.1 # CVE-2026-56855 / CVE-2026-78662 are the same temporary exception documented in # .trivyignore.yaml: Trivy 0.74.0 still embeds golang.org/x/crypto v0.55.0, while the # 0.56.0 fix (published 2026-09-02) hasn't reached any Trivy release, or even Trivy diff --git a/.trivyignore.yaml b/.trivyignore.yaml index 28c3b7f0a9..715c7b625e 100644 --- a/.trivyignore.yaml +++ b/.trivyignore.yaml @@ -176,6 +176,25 @@ vulnerabilities: - "pkg:golang/google.golang.org/grpc" expired_at: 2026-10-15 + # CVE-2026-84445 is a DoS in grpc-go servers built with `xds.NewGRPCServer()`: a request + # carrying neither `:authority` nor `Host` reaches the xDS routing interceptor, which + # indexes an empty slice of authorities and panics. The per-RPC goroutine does not + # recover, so the whole server process dies. Fixed in 1.82.2 and 1.83.2 (published + # 2026-09-08). Trivy 0.74.0, the latest published release and the version the images + # ship, pins 1.82.1 as an indirect dependency: + # https://github.com/aquasecurity/trivy/blob/v0.74.0/go.mod + # Trivy main already carries 1.83.2, but no published release includes it yet. + # The reachability argument is the one made for CVE-2026-84304 above, only narrower: + # this panic needs an xDS-managed gRPC server. Prowler invokes Trivy exclusively as + # `trivy image` and `trivy fs` on a local path, never `trivy server`, so the image runs + # no gRPC server at all, xDS or otherwise. Remove this temporary suppression as soon as + # a Trivy release pins grpc >= 1.83.2. + # https://github.com/advisories/GHSA-2v4p-qf9q-27wj + - id: CVE-2026-84445 + purls: + - "pkg:golang/google.golang.org/grpc@v1.82.1" + expired_at: 2026-10-15 + # CVE-2026-56855 and CVE-2026-78662 are DoS deadlocks in x/crypto/ssh: a malicious peer # can flood or misuse channel messages (RFC 4254) to block the whole connection. # Fixed in golang.org/x/crypto v0.56.0 (published 2026-09-02). Trivy 0.74.0, the latest