Releases: GoogleCloudPlatform/gcsfuse
Releases · GoogleCloudPlatform/gcsfuse
Release list
Gcsfuse v3.12.1
fix: Upgrading dependencies (crypto & go-toml) package (#5116) * Updating cyrpto package to v0.56 * Upgrading go-toml package to v2.4.3
Gcsfuse v3.5.10
Upgrading dependencies to fix CVEs
Gcsfuse v3.12.0
test(list_large_dir): check if bucket dir is empty before creating fi…
Gcsfuse v3.11.4
CVE Fixes:
| Dependency | CVE | Summary |
|---|---|---|
| google.golang.org/grpc (v1.82.1 → v1.83.1) | CVE-2026-84304 | Uncontrolled resource consumption and remote Denial of Service (DoS) via HTTP/2 receive-buffer memory exhaustion in transport [PR#5088] |
Gcsfuse v3.8.4
Bug fixes
- Rapid Bucket Startup Optimization: Accelerated startup for Rapid buckets by skipping redundant DirectPath connectivity checks [PR#5027]
Gcsfuse v2.5.5
build(deps): upgrade golang and packages for CVE fixes (#5051) * build(deps): upgrade golang and packages for CVE fixes
Gcsfuse v3.11.3
Bug fixes & Improvements:
- Stat Cache Bug Fix: Addressed a bug where windowed listing operations incorrectly added negative entries to the stat cache in rare scenarios, resulting in erroneous ENOENT (File Not Found) responses for implicit directories [PR#5025].
- Mount Optimization: Disabled internal Go SDK retries for DirectPath connectivity verification to prevent mounting from getting stalled during transient network issues[PR#4993].
- Rapid Bucket Startup Optimization: Accelerated startup for Rapid buckets by skipping redundant DirectPath connectivity checks [PR#5027]
Dependency Upgrades / CVE fixes:
| CVE | CVE Description |
|---|---|
| CVE-2026-39830 | Client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh |
| CVE-2026-39831 | Bypass of FIDO/U2F security keys physical user presence interaction in golang.org/x/crypto/ssh |
| CVE-2026-39832 | Agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent |
| CVE-2026-39833 | Key constraints not enforced in golang.org/x/crypto/ssh/agent |
| CVE-2026-39834 | Infinite loop on large channel writes in golang.org/x/crypto/ssh |
| CVE-2026-39821 | Failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| CVE-2026-42508 | Auth bypass via unenforced revoked status in golang.org/x/crypto/ssh/knownhosts |
| CVE-2026-42499 | Quadratic string concatenation in consumePhrase in net/mail |
| CVE-2026-33814 | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 and golang.org/x/net |
Gcsfuse v2.11.6
build(deps): upgrade Go to 1.26.7 and dependencies for CVE remediatio…
Gcsfuse v3.2.8
Several CVEs were fixed:
| Dependency | CVE | Summary |
|---|---|---|
| Go stdlib (1.26.3 → 1.26.7) | CVE-2026-27145 | Inefficient candidate hostname parsing in crypto/x509 |
| Go stdlib (1.26.3 → 1.26.7) | CVE-2026-33818 | Enforce maximum recursion depth in encoding/asn1 |
| Go stdlib (1.26.3 → 1.26.7) | CVE-2026-39822 | Root escape via symlink plus trailing slash in os |
| Go stdlib (1.26.3 → 1.26.7) | CVE-2026-42504 | Quadratic complexity in WordDecoder.DecodeHeader in mime |
| Go stdlib (1.26.3 → 1.26.7) | CVE-2026-42505 | Invoking Encrypted Client Hello privacy leak in crypto/tls |
| Go stdlib (1.26.3 → 1.26.7) | CVE-2026-42507 | Arbitrary inputs are included in errors without any escaping in net/textproto |
| Go stdlib (1.26.3 → 1.26.7) | CVE-2026-56853 | Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http |
| Go stdlib (1.26.3 → 1.26.7) | CVE-2026-56858 | Fix JavaScript regex context tracking in html/template |
| Go stdlib (1.26.3 → 1.26.7) | CVE-2026-56859 | Add recursion depth guard during decode in encoding/xml |
| Go stdlib (1.26.3 → 1.26.7) | CVE-2026-56860 | Avoid quadratic complexity in resolvePath in net/url |
| Go stdlib (1.26.3 → 1.26.7) | CVE-2026-56862 | Limit handshake messages accepted post-handshake in crypto/tls |
| go.opentelemetry.io/otel (v1.43.0 → v1.45.0) | CVE-2026-41178 | Baggage parsing no longer caps raw header length |
| golang.org/x/crypto (v0.51.0 → v0.55.0) | CVE-2026-39827 | Invoking memory leak when rejecting channels can lead to DoS in ssh |
| golang.org/x/crypto (v0.51.0 → v0.55.0) | CVE-2026-39828 | Invoking bypass of certificate restrictions in ssh |
| golang.org/x/crypto (v0.51.0 → v0.55.0) | CVE-2026-39829 | Invoking pathological RSA/DSA parameters may cause DoS in ssh |
| golang.org/x/crypto (v0.51.0 → v0.55.0) | CVE-2026-39830 | Invoking client can cause server deadlock on unexpected responses in ssh |
| golang.org/x/crypto (v0.51.0 → v0.55.0) | CVE-2026-39831 | Invoking bypass of FIDO/U2F security keys physical interaction in ssh |
| golang.org/x/crypto (v0.51.0 → v0.55.0) | CVE-2026-39832 | Invoking agent constraints dropped when forwarding keys in ssh/agent |
| golang.org/x/crypto (v0.51.0 → v0.55.0) | CVE-2026-39833 | Invoking key constraints not enforced in ssh/agent |
| golang.org/x/crypto (v0.51.0 → v0.55.0) | CVE-2026-39834 | Invoking infinite loop on large channel writes in ssh |
| golang.org/x/crypto (v0.51.0 → v0.55.0) | CVE-2026-39835 | Invoking server panic during CheckHostKey/Authenticate in ssh |
| golang.org/x/crypto (v0.51.0 → v0.55.0) | CVE-2026-42508 | Invoking auth bypass via unenforced @revoked status in ssh/knownhosts |
| golang.org/x/crypto (v0.51.0 → v0.55.0) | CVE-2026-46595 | Invoking VerifiedPublicKeyCallback permissions skip enforcement in ssh |
| golang.org/x/crypto (v0.51.0 → v0.55.0) | CVE-2026-46597 | Invoking byte arithmetic causes underflow and panic in ssh |
| golang.org/x/crypto (v0.51.0 → v0.55.0) | CVE-2026-46598 | Invoking pathological inputs can lead to client panic in ssh/agent |
| golang.org/x/net (v0.54.0 → v0.58.0) | CVE-2026-25680 | Invoking denial of service when parsing arbitrary HTML in html |
| golang.org/x/net (v0.54.0 → v0.58.0) | CVE-2026-25681 | Invoking incorrect handling of character references in DOCTYPE nodes in html |
| golang.org/x/net (v0.54.0 → v0.58.0) | CVE-2026-27136 | Invoking duplicate attributes can cause XSS in html |
| golang.org/x/net (v0.54.0 → v0.58.0) | CVE-2026-39821 | Invoking failure to reject ASCII-only Punycode-encoded labels in idna |
| golang.org/x/net (v0.54.0 → v0.58.0) | CVE-2026-42502 | Invoking incorrect handling of HTML elements in foreign content in html |
| golang.org/x/net (v0.54.0 → v0.58.0) | CVE-2026-42506 | Invoking incorrect handling of namespaced elements in foreign content in html |
| golang.org/x/net (v0.54.0 → v0.58.0) | CVE-2026-46600 | Parsing an invalid SVCB or HTTPS RR can panic in dns/dnsmessage |
| golang.org/x/text (v0.37.0 → v0.41.0) | CVE-2026-56852 | Infinite loop on invalid input |
| google.golang.org/grpc (v1.74.2 → v1.83.1) | CVE-2026-33186 | Authorization bypass via missing leading slash in :path |
| google.golang.org/grpc (v1.74.2 → v1.83.1) | GHSA-hrxh-6v49-42gf / GO-2026-6061 | Vulnerabilities in the xDS RBAC authorization engine and HTTP/2 transport |
Gcsfuse v3.8.3
CVE Fixes:
| Dependency | CVE | Summary |
|---|---|---|
| github.com/go-jose/go-jose/v4 (v4.1.3 → v4.1.4) | CVE-2026-34986 | Go JOSE Panics in JWE decryption |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-27145 | Inefficient candidate hostname parsing in crypto/x509 |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-33811 | Crash when handling long CNAME response in net |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-33818 | Enforce maximum recursion depth in encoding/asn1 |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-39820 | Quadratic string concatenation in consumeComment in net/mail |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-39822 | Root escape via symlink plus trailing slash in os |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-39823 | Bypass of meta content URL escaping causes XSS in html/template |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-39825 | ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-39826 | Escaper bypass leads to XSS in html/template |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-39836 | Panic in Dial and LookupPort when handling NUL byte on Windows in net |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-42499 | Quadratic string concatenation in consumePhrase in net/mail |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-42504 | Quadratic complexity in WordDecoder.DecodeHeader in mime |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-42505 | Invoking Encrypted Client Hello privacy leak in crypto/tls |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-42507 | Arbitrary inputs are included in errors without any escaping in net/textproto |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-56853 | Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-56858 | Fix JavaScript regex context tracking in html/template |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-56859 | Add recursion depth guard during decode in encoding/xml |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-56860 | Avoid quadratic complexity in resolvePath in net/url |
| Go stdlib (1.26.2 → 1.26.6) | CVE-2026-56862 | Limit handshake messages accepted post-handshake in crypto/tls |
| go.opentelemetry.io/otel/sdk (v1.42.0 → v1.45.0) | CVE-2026-39883 | BSD kenv command not using absolute path enables PATH hijacking |
| golang.org/x/crypto (v0.49.0 → v0.54.0) | CVE-2026-39827 | Invoking memory leak when rejecting channels can lead to DoS in ssh |
| golang.org/x/crypto (v0.49.0 → v0.54.0) | CVE-2026-39828 | Invoking bypass of certificate restrictions in ssh |
| golang.org/x/crypto (v0.49.0 → v0.54.0) | CVE-2026-39829 | Invoking pathological RSA/DSA parameters may cause DoS in ssh |
| golang.org/x/crypto (v0.49.0 → v0.54.0) | CVE-2026-39830 | Invoking client can cause server deadlock on unexpected responses in ssh |
| golang.org/x/crypto (v0.49.0 → v0.54.0) | CVE-2026-39831 | Invoking bypass of FIDO/U2F security keys physical interaction in ssh |
| golang.org/x/crypto (v0.49.0 → v0.54.0) | CVE-2026-39832 | Invoking agent constraints dropped when forwarding keys in ssh/agent |
| golang.org/x/crypto (v0.49.0 → v0.54.0) | CVE-2026-39833 | Invoking key constraints not enforced in ssh/agent |
| golang.org/x/crypto (v0.49.0 → v0.54.0) | CVE-2026-39834 | Invoking infinite loop on large channel writes in ssh |
| golang.org/x/crypto (v0.49.0 → v0.54.0) | CVE-2026-39835 | Invoking server panic during CheckHostKey/Authenticate in ssh |
| golang.org/x/crypto (v0.49.0 → v0.54.0) | CVE-2026-42508 | Invoking auth bypass via unenforced @revoked status in ssh/knownhosts |
| golang.org/x/crypto (v0.49.0 → v0.54.0) | CVE-2026-46595 | Invoking VerifiedPublicKeyCallback permissions skip enforcement in ssh |
| golang.org/x/crypto (v0.49.0 → v0.54.0) | CVE-2026-46597 | Invoking byte arithmetic causes underflow and panic in ssh |
| golang.org/x/crypto (v0.49.0 → v0.54.0) | CVE-2026-46598 | Invoking pathological inputs can lead to client panic in ssh/agent |
| golang.org/x/net (v0.52.0 → v0.56.0) | CVE-2026-25680 | Invoking denial of service when parsing arbitrary HTML in html |
| golang.org/x/net (v0.52.0 → v0.56.0) | CVE-2026-25681 | Invoking incorrect handling of character references in DOCTYPE nodes in html |
| golang.org/x/net (v0.52.0 → v0.56.0) | CVE-2026-27136 | Invoking duplicate attributes can cause XSS in html |
| golang.org/x/net (v0.52.0 → v0.56.0) | CVE-2026-33814 | Infinite loop in HTTP/2 transport with bad SETTINGS_MAX_FRAME_SIZE in http2 |
| golang.org/x/net (v0.52.0 → v0.56.0) | CVE-2026-39821 | Invoking failure to reject ASCII-only Punycode-encoded labels in idna |
| golang.org/x/net (v0.52.0 → v0.56.0) | CVE-2026-42502 | Invoking incorrect handling of HTML elements in foreign content in html |
| golang.org/x/net (v0.52.0 → v0.56.0) | CVE-2026-42506 | Invoking incorrect handling of namespaced elements in foreign content in html |
| golang.org/x/net (v0.52.0 → v0.56.0) | CVE-2026-46600 | Parsing an invalid SVCB or HTTPS RR can panic in dns/dnsmessage |
| golang.org/x/sys (v0.42.0 → v0.47.0) | CVE-2026-39824 | Invoking integer overflow in NewNTUnicodeString in windows |
| golang.org/x/text (v0.35.0 → v0.40.0) | CVE-2026-56852 | Infinite loop on invalid input in golang.org/x/text |
| google.golang.org/grpc (v1.79.3 → v1.83.0) | GHSA-hrxh-6v49-42gf / GO-2026-6061 | Vulnerabilities in the xDS RBAC authorization engine and HTTP/2 transport |