[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:21151-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-01T00:21:03.480Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":24,"duplicates":25,"related":26,"reserved_at":9,"published_at":32,"modified_at":33,"state":9,"summary":34,"references_raw":36,"kevs":80,"epss":9,"epss_history":81,"metrics":82,"affected":83},"OPENSUSE-SU-2026:21151-1","Security update for warewulf4\n\nThis update for warewulf4 fixes the following issues:\n\nChanges in warewulf4:\n\n- updated go-jose to fix CVE-2026-34986 (bsc#1262810)\n- chi is fixed in the upstream project\n\n- updating to v4.7.0 with following security fixes\n * fixed CVE-2026-39821 (bsc#1266483)\n * fixed CVE-2026-33814 (bsc#1265653)\n- v4.7.0 with significant changes relative to the v4.6.x series which are:\n  * New wwctl unset command\n  * Refactored server routes (URLs)\n  * New /files/ route for serving individual files and templates\n  * Server TLS support\n  * Removed support for fetching individual overlays and individual files from overlays\n  * Fixed whitespace handling around template functions\n  * Security fixes, including updated Go and library versions\n- changes from v4.6.5:\n  * new wwctl overlay info command\n  * fixed wwctl image import --update option\n  * cross-arch support for wwclient\n  * improved IPv6 support\n  * improved support for bonded interfaces\n  * renamed debian.interfaces overlay to ifupdown\n  * new systemd-networkd overlay\n  * warewulf-dracut fixes, including \"provision-to-disk\" fixes\n- remove slurm-overlay package\n\n- fix CVE-2025-69725 (bsc#1258511) by updating chi\n\n- updated to v4.6.5 with following changes:\n  * new wwctl overlay info command\n  * fixed wwctl image import --update option (bsc#1254470)\n  * cross-arch support for wwclient\n  * improved IPv6 support\n  * improved support for bonded interfaces\n  * renamed debian.interfaces overlay to ifupdown\n  * new systemd-networkd overlay\n  * warewulf-dracut fixes, including \"provision-to-disk\" fixes\n- default to dnsmasq instead of dhcpd and tftp\n",null,[],[],[],[14,16,18,20,22],{"_key":15},"CVE-2025-58058",{"_key":17},"CVE-2025-69725",{"_key":19},"CVE-2026-33814",{"_key":21},"CVE-2026-34986",{"_key":23},"CVE-2026-39821",[],[],[27,28,29,30,31],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},"2026-06-23T09:37:25Z","2026-06-30T18:24:45.673043944Z",{"cisa_kev":35,"cisa_ransomware":35,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[37,43,47,51,55,59,64,68,72,76],{"url":38,"sources":39,"tags":41},"https://bugzilla.suse.com/1254470",[40],"osv_opensuse",[42],"REPORT",{"url":44,"sources":45,"tags":46},"https://bugzilla.suse.com/1258511",[40],[42],{"url":48,"sources":49,"tags":50},"https://bugzilla.suse.com/1262810",[40],[42],{"url":52,"sources":53,"tags":54},"https://bugzilla.suse.com/1265653",[40],[42],{"url":56,"sources":57,"tags":58},"https://bugzilla.suse.com/1266483",[40],[42],{"url":60,"sources":61,"tags":62},"https://www.suse.com/security/cve/CVE-2025-58058",[40],[63],"WEB",{"url":65,"sources":66,"tags":67},"https://www.suse.com/security/cve/CVE-2025-69725",[40],[63],{"url":69,"sources":70,"tags":71},"https://www.suse.com/security/cve/CVE-2026-33814",[40],[63],{"url":73,"sources":74,"tags":75},"https://www.suse.com/security/cve/CVE-2026-34986",[40],[63],{"url":77,"sources":78,"tags":79},"https://www.suse.com/security/cve/CVE-2026-39821",[40],[63],[],[],[],[84],{"ecosystem":85,"name":86,"vendor":87,"product":88,"cpe_part":9,"purl_type":89,"purl_namespace":87,"purl_name":88,"source":9,"versions":90},"openSUSE","warewulf4","opensuse","warewulf4&distro=openSUSE Leap 16.0","rpm",[91],{"version":92,"is_range":93,"range_type":94,"version_start":9,"version_start_type":9,"version_end":95,"version_end_type":96,"fixed_in":9},"lt4_7_0_bp160_1_1",true,"ecosystem","4.7.0-bp160.1.1","excluding"]