Please update google.golang.org/grpc to 1.82.2 or 1.83.2 to fix CVE-2026-84445
Closed
Beginner friendly
- Dominant language
- Go
- Stars
- 2.2k
- Forks
- 662
- Avg merge
- 3d 22h
- Merged PRs (30d)
- 24
Description
The vendored dependency version 1.82.1 of `google.golang.org/grpc` is affected by CVE-2026-84445.
Could you please update this dependency to address this CVE?
Contributor guide
Research direction
Start by locating the vendored google.golang.org/grpc 1.82.1 reference and its dependency metadata. Update it to 1.82.2 or 1.83.2, verify that the vulnerable version is no longer present, and run the repository's Go tests to confirm the dependency update is safe.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- backend, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 75/100