[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:21084-1":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T11:35:27.363Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":46,"duplicates":47,"related":48,"reserved_at":9,"published_at":65,"modified_at":66,"state":9,"summary":67,"references_raw":69,"kevs":153,"epss":9,"epss_history":154,"metrics":155,"affected":156},"OPENSUSE-SU-2026:21084-1","Security update for distribution\n\nThis update for distribution fixes the following issues\n\n- CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE\n  (bsc#1265788).\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation\n  bypass and privilege escalation (bsc#1266629).\n- CVE-2026-41888: tag deletion bypasses the storage.delete.enabled configuration (bsc#1265429).\n- CVE-2026-39827: Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh (bsc#1266049).\n- CVE-2026-39828: Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh (bsc#1266049).\n- CVE-2026-39829: Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh (bsc#1266049).\n- CVE-2026-39830: Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh\n  (bsc#1266049).\n- CVE-2026-39831: Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh\n  (bsc#1266049).\n- CVE-2026-39832: Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent\n  (bsc#1266049).\n- CVE-2026-39833: Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent (bsc#1266049).\n- CVE-2026-39834: Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh (bsc#1266049).\n- CVE-2026-39835: Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh (bsc#1266049).\n- CVE-2026-42508: Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts\n  (bsc#1266049).\n- CVE-2026-46595: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh\n  (bsc#1266049).\n- CVE-2026-46597: Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh (bsc#1266049).\n- CVE-2026-46598: Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent (bsc#1266049).\n\nChanges:\n\n * Bounds-check the file basename in PurgeUploads Walk callback\n * Add S3 Express One Zone support to the S3 storage driver\n * Fix tag list endpoint in proxy mode\n * Clamp oversized `n` query parameter in proxy mode instead of\n returning 400\n * See the full changelog below for the full list of changes.\n * internal/client/auth/challenge: cleanups and minor refactor\n * build(deps): bump\n go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp\n from 0.18.0 to 0.19.0 in the go_modules group across 1\n directory\n * build(deps): bump go.opentelemetry.io/otel/exporters/otlp/otl\n ptrace/otlptracehttp from 1.42.0 to 1.43.0 in the go_modules\n group across 1 directory\n * build(deps): bump github/codeql-action from 4.34.1 to 4.35.1\n * chore(build): Bump go version to latest\n * refactor: use slices.Backward to simplify the code\n * fix(proxy): fix tag list endpoint in proxy mode\n * Update docker-compose structure in deploying.md\n * build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1\n * build(deps): bump actions/upload-pages-artifact from 4.0.0 to\n 5.0.0\n * build(deps): bump docker/login-action from 4.0.0 to 4.1.0\n * build(deps): bump docker/bake-action from 7.0.0 to 7.1.0\n * fix(proxy): clamp oversized n query param instead of\n * feat(s3): add express zone one support to S3 driver\n * fix(storage): bounds-check the file basename in PurgeUploads\n Walk callback\n * chore(release): prepare for v3.1.1 release\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44],{"_key":15},"CVE-2026-33814",{"_key":17},"CVE-2026-39821",{"_key":19},"CVE-2026-39827",{"_key":21},"CVE-2026-39828",{"_key":23},"CVE-2026-39829",{"_key":25},"CVE-2026-39830",{"_key":27},"CVE-2026-39831",{"_key":29},"CVE-2026-39832",{"_key":31},"CVE-2026-39833",{"_key":33},"CVE-2026-39834",{"_key":35},"CVE-2026-39835",{"_key":37},"CVE-2026-41888",{"_key":39},"CVE-2026-42508",{"_key":41},"CVE-2026-46595",{"_key":43},"CVE-2026-46597",{"_key":45},"CVE-2026-46598",[],[],[49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},"2026-06-18T14:30:03Z","2026-06-30T18:24:39.660051143Z",{"cisa_kev":68,"cisa_ransomware":68,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[70,76,80,84,88,93,97,101,105,109,113,117,121,125,129,133,137,141,145,149],{"url":71,"sources":72,"tags":74},"https://bugzilla.suse.com/1265429",[73],"osv_opensuse",[75],"REPORT",{"url":77,"sources":78,"tags":79},"https://bugzilla.suse.com/1265788",[73],[75],{"url":81,"sources":82,"tags":83},"https://bugzilla.suse.com/1266049",[73],[75],{"url":85,"sources":86,"tags":87},"https://bugzilla.suse.com/1266629",[73],[75],{"url":89,"sources":90,"tags":91},"https://www.suse.com/security/cve/CVE-2026-33814",[73],[92],"WEB",{"url":94,"sources":95,"tags":96},"https://www.suse.com/security/cve/CVE-2026-39821",[73],[92],{"url":98,"sources":99,"tags":100},"https://www.suse.com/security/cve/CVE-2026-39827",[73],[92],{"url":102,"sources":103,"tags":104},"https://www.suse.com/security/cve/CVE-2026-39828",[73],[92],{"url":106,"sources":107,"tags":108},"https://www.suse.com/security/cve/CVE-2026-39829",[73],[92],{"url":110,"sources":111,"tags":112},"https://www.suse.com/security/cve/CVE-2026-39830",[73],[92],{"url":114,"sources":115,"tags":116},"https://www.suse.com/security/cve/CVE-2026-39831",[73],[92],{"url":118,"sources":119,"tags":120},"https://www.suse.com/security/cve/CVE-2026-39832",[73],[92],{"url":122,"sources":123,"tags":124},"https://www.suse.com/security/cve/CVE-2026-39833",[73],[92],{"url":126,"sources":127,"tags":128},"https://www.suse.com/security/cve/CVE-2026-39834",[73],[92],{"url":130,"sources":131,"tags":132},"https://www.suse.com/security/cve/CVE-2026-39835",[73],[92],{"url":134,"sources":135,"tags":136},"https://www.suse.com/security/cve/CVE-2026-41888",[73],[92],{"url":138,"sources":139,"tags":140},"https://www.suse.com/security/cve/CVE-2026-42508",[73],[92],{"url":142,"sources":143,"tags":144},"https://www.suse.com/security/cve/CVE-2026-46595",[73],[92],{"url":146,"sources":147,"tags":148},"https://www.suse.com/security/cve/CVE-2026-46597",[73],[92],{"url":150,"sources":151,"tags":152},"https://www.suse.com/security/cve/CVE-2026-46598",[73],[92],[],[],[],[157],{"ecosystem":158,"name":159,"vendor":160,"product":161,"cpe_part":9,"purl_type":162,"purl_namespace":160,"purl_name":161,"source":9,"versions":163},"openSUSE","distribution","opensuse","distribution&distro=openSUSE Leap 16.0","rpm",[164],{"version":165,"is_range":166,"range_type":167,"version_start":9,"version_start_type":9,"version_end":168,"version_end_type":169,"fixed_in":9},"lt3_1_1_160000_1_1",true,"ecosystem","3.1.1-160000.1.1","excluding"]