Remediation for Critical and High Vulnerabilities in IDSP (OPA, Spring AI, Go Crypto)
search cancel

Remediation for Critical and High Vulnerabilities in IDSP (OPA, Spring AI, Go Crypto)

book

Article ID: 444735

calendar_today

Updated On:

Products

Symantec Identity Security Platform - IDSP (formerly VIP Authentication Hub)

Issue/Introduction

Vulnerability scans (e.g., JFrog Xray, Snyk) performed on Symantec Identity Security Platform - IDSP (formerly VIP Authentication Hub) images identify multiple Critical and High vulnerabilities. Impacted components include:
- OPA (Open Policy Agent)
- Spring AI (spring-ai-model)
- Go Crypto libraries (golang.org/x/crypto)
- Containerd

Specific Vulnerabilities Identified:
- CVE-2026-39832/33/30/34/31: Critical vulnerabilities in `golang.org/x/crypto` related to SSH key constraints, integer overflows, and FIDO/U2F verification.
- CVE-2026-41712: High vulnerability in Spring AI chat memory regarding unintended data exposure.
- CVE-2026-46680: High vulnerability in `containerd` allowing `runAsNonRoot` evasion.
- CVE-2026-39821: Critical vulnerability in `golang.org/x/net` related to Punycode/IDNA processing.

Environment

Symantec Identity Security Platform - IDSP (formerly VIP Authentication Hub) 

Release: 4.0.2

Cause

These vulnerabilities are typically found in the upstream third-party packages or older versions of service images (e.g., `admin-svc`, `authmgr`, `opa`) bundled with the VIP Authentication Hub platform.

Resolution

Broadcom Engineering has addressed these vulnerabilities through component upgrades and patches in the following releases:

Upgrade to Release 4.0.3 (Recommended)
The majority of the Critical and High vulnerabilities identified in the 4.0.2.x series are remediated in the 4.0.3 release. This release includes updated IDSP (Identity Security Platform) images with the latest security patches. Please contact Broadcom Support if you have any questions related to the fixes.