[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:21136-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-01T00:21:03.480Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":20,"duplicates":21,"related":22,"reserved_at":9,"published_at":26,"modified_at":27,"state":9,"summary":28,"references_raw":30,"kevs":58,"epss":9,"epss_history":59,"metrics":60,"affected":61},"OPENSUSE-SU-2026:21136-1","Security update for golang-github-prometheus-alertmanager\n\nThis update for golang-github-prometheus-alertmanager fixes the following issues:\n\nChanges in golang-github-prometheus-alertmanager:\n\n- Update to version 0.28.1 (jsc#PED-13285):\n  * Improved performance of inhibition rules when using Equal\n    labels.\n  * Improve the documentation on escaping in UTF-8 matchers.\n  * Update alertmanager_config_hash metric help to document the\n    hash is not cryptographically strong.\n  * Fix panic in amtool when using --verbose.\n  * Fix templating of channel field for Rocket.Chat.\n  * Fix rocketchat_configs written as rocket_configs in docs.\n  * Fix usage for --enable-feature flag.\n  * Trim whitespace from OpsGenie API Key.\n  * Fix Jira project template not rendered when searching for\n    existing issues.\n  * Fix subtle bug in JSON/YAML encoding of inhibition rules that\n    would cause Equal labels to be omitted.\n  * Fix header for slack_configs in docs.\n  * Fix weight and wrap of Microsoft Teams notifications.\n\n- Upgrade to version 0.28.0:\n  * CVE-2025-47908: Bump github.com/rs/cors (bsc#1247748).\n  * Templating errors in the SNS integration now return an error.\n  * Adopt log/slog, drop go-kit/log.\n  * Add a new Microsoft Teams integration based on Flows.\n  * Add a new Rocket.Chat integration.\n  * Add a new Jira integration.\n  * Add support for GOMEMLIMIT, enable it via the feature flag\n    --enable-feature=auto-gomemlimit.\n  * Add support for GOMAXPROCS, enable it via the feature flag\n    --enable-feature=auto-gomaxprocs.\n  * Add support for limits of silences including the maximum number\n    of active and pending silences, and the maximum size per\n    silence (in bytes). You can use the flags\n    --silences.max-silences and --silences.max-silence-size-bytes\n    to set them accordingly.\n  * Muted alerts now show whether they are suppressed or not in\n    both the /api/v2/alerts endpoint and the Alertmanager UI.\n\n- Upgrade to version 0.27.0:\n  * API: Removal of all api/v1/ endpoints. These endpoints\n    now log and return a deprecation message and respond with a\n    status code of 410.\n  * UTF-8 Support: Introduction of support for any UTF-8\n    character as part of label names and matchers.\n  * Discord Integration: Enforce max length in message.\n  * Metrics: Introduced the experimental feature flag\n    --enable-feature=receiver-name-in-metrics to include the\n    receiver name.\n  * Metrics: Introduced a new gauge named\n    alertmanager_inhibition_rules that counts the number of\n    configured inhibition rules.\n  * Metrics: Introduced a new counter named\n    alertmanager_alerts_supressed_total that tracks muted alerts,\n    it contains a reason label to indicate the source of the mute.\n  * Discord Integration: Introduced support for webhook_url_file.\n  * Microsoft Teams Integration: Introduced support for\n    webhook_url_file.\n  * Microsoft Teams Integration: Add support for summary.\n  * Metrics: Notification metrics now support two new values for\n    the label reason, contextCanceled and contextDeadlineExceeded.\n  * Email Integration: Contents of auth_password_file are now\n    trimmed of prefixed and suffixed whitespace.\n  * amtool: Fixes the error scheme required for webhook url when\n    using amtool with --alertmanager.url.\n  * Mixin: Fix AlertmanagerFailedToSendAlerts,\n    AlertmanagerClusterFailedToSendAlerts, and\n    AlertmanagerClusterFailedToSendAlerts to make sure they ignore\n    the reason label.\n\n- Security:\n  * Fix proxy bypassing using IPv6 zone IDs\n    (CVE-2025-22870, bsc#1238686)\n  * Fix HTTP/2 CONTINUATION flood in net/http\n    (CVE-2023-45288, bsc#1236516)\n  * Add 0002-Bump-x-net.patch\n",null,[],[],[],[14,16,18],{"_key":15},"CVE-2023-45288",{"_key":17},"CVE-2025-22870",{"_key":19},"CVE-2025-47908",[],[],[23,24,25],{"_key":15},{"_key":17},{"_key":19},"2026-06-18T08:21:46Z","2026-06-30T18:24:44.560080982Z",{"cisa_kev":29,"cisa_ransomware":29,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[31,37,41,45,50,54],{"url":32,"sources":33,"tags":35},"https://bugzilla.suse.com/1236516",[34],"osv_opensuse",[36],"REPORT",{"url":38,"sources":39,"tags":40},"https://bugzilla.suse.com/1238686",[34],[36],{"url":42,"sources":43,"tags":44},"https://bugzilla.suse.com/1247748",[34],[36],{"url":46,"sources":47,"tags":48},"https://www.suse.com/security/cve/CVE-2023-45288",[34],[49],"WEB",{"url":51,"sources":52,"tags":53},"https://www.suse.com/security/cve/CVE-2025-22870",[34],[49],{"url":55,"sources":56,"tags":57},"https://www.suse.com/security/cve/CVE-2025-47908",[34],[49],[],[],[],[62],{"ecosystem":63,"name":64,"vendor":65,"product":66,"cpe_part":9,"purl_type":67,"purl_namespace":65,"purl_name":66,"source":9,"versions":68},"openSUSE","golang-github-prometheus-alertmanager","opensuse","golang-github-prometheus-alertmanager&distro=openSUSE Leap 16.0","rpm",[69],{"version":70,"is_range":71,"range_type":72,"version_start":9,"version_start_type":9,"version_end":73,"version_end_type":74,"fixed_in":9},"lt0_28_1_bp160_1_1",true,"ecosystem","0.28.1-bp160.1.1","excluding"]