Skip to content

CVE-2026-33186: upgrade google.golang.org/grpc in openconfig/lemming submodule to ≥v1.82.1 #43

Description

@qiluo-msft

CVE

CVE-2026-33186 — gRPC-Go authz policy bypass (advisory)
Fix requires: google.golang.org/grpc ≥ v1.82.1

Affected file

src/libsai-grpc/lemming/go.mod (submodule: openconfig/lemming)

  • Current: google.golang.org/grpc v1.71.0
  • Required: ≥ v1.82.1

Context

The top-level src/go.mod was already upgraded to grpc v1.82.1 in PR #42, but the nested lemming/go.mod remains at v1.71.0. This is a non-production submodule (AlpineVS SAI gRPC).

Suggested fix

File a PR in openconfig/lemming to upgrade grpc, then update the submodule pin here once merged.

Scan reference

Found by DVD-R scan_image_vulnerabilities scan of sonic-buildimage on Aug 20, 2026.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions