[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:21251-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-01T00:21:03.480Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":66,"duplicates":67,"related":68,"reserved_at":9,"published_at":95,"modified_at":96,"state":9,"summary":97,"references_raw":99,"kevs":247,"epss":9,"epss_history":248,"metrics":249,"affected":250},"OPENSUSE-SU-2026:21251-1","Security update for alloy\n\nThis update for alloy fixes the following issues:\n\nUpdate to version 1.17.0.\n\nSecurity issues fixed:\n\n- CVE-2026-25680: golang.org/x/net/html: parsing arbitrary HTML can consume excessive CPU time, possibly leading to\n  denial of service (bsc#1267185).\n- CVE-2026-25681: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an\n  unexpected HTML tree and allows for XSS (bsc#1267185).\n- CVE-2026-27136: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an\n  unexpected HTML tree and allows for XSS (bsc#1267185).\n- CVE-2026-33532: yaml: parsing input with deeply nestes collections may throw a `RangeError` due to a stack overflow\n  and cause to a denial of service (bsc#1260981).\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation\n  bypass and privilege escalation (bsc#1266654).\n- CVE-2026-39827: golang.org/x/crypto/ssh: authenticated SSH clients that repeatedly open channels which were rejected\n  by the server can cause unbounded memory growth and a crash (bsc#1266196).\n- CVE-2026-39828: golang.org/x/crypto/ssh: permissions discarded when an SSH server authentication callback returns\n  `PartialSuccessError` with non-`nil` permissions (bsc#1266196).\n- CVE-2026-39829: golang.org/x/crypto/ssh: unenforced size limits on key parameters by the the RSA and DSA public key\n  parsers can lead to excessive CPU consumption when processing a crafted public key (bsc#1266196).\n- CVE-2026-39830: golang.org/x/crypto/ssh: malicious SSH peers sending unsolicited global request responses can block a\n  connection's read loop and cause a resource leak (bsc#1266196).\n- CVE-2026-39831: golang.org/x/crypto/ssh: missing `User Presence` flag checks in the `Verify()` method for FIDO/U2F\n  security key types cause signatures generated without physical touch to be accepted (bsc#1266196).\n- CVE-2026-39832: golang.org/x/crypto/ssh: destination restrictions are silently stripped when forwarding keys and\n  allow for unrestricted use of a key on a remote host (bsc#1266196).\n- CVE-2026-39833: golang.org/x/crypto/ssh: in-memory keyring returned by `NewKeyring()` silently accepts keys with the\n  `ConfirmBeforeUse` constraint but never enforces it (bsc#1266196).\n- CVE-2026-39834: golang.org/x/crypto/ssh: writing data larger than 4GB in a single `Write` call on an SSH channel\n  leads to an integer overflow and an infinite loop that sends empty packets (bsc#1266196).\n- CVE-2026-39835: golang.org/x/crypto/ssh: processing of certificates by SSH servers using `CertChecker` as a public\n  key callback without setting `IsUserAuthority` or `IsHostAuthority` can lead to a panic (bsc#1266196).\n- CVE-2026-41889: github.com/jackc/pgx/v5/internal/sanitize: use placeholders in dollar-quoted string literals in an\n  SQL query can lead to a SQL injection (bsc#1265440).\n- CVE-2026-42502: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an\n  unexpected HTML tree and allows for XSS (bsc#1267185).\n- CVE-2026-42506: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an\n  unexpected HTML tree and allows for XSS (bsc#1267185).\n- CVE-2026-42508: golang.org/x/crypto/ssh: revoked `SignatureKey`s belonging to a CA are not correctly checked for\n  revocation (bsc#1266196).\n- CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via\n  infinite loops, panics or resource consumption (bsc#1267333).\n- CVE-2026-45678: go.opentelemetry.io/obi: Postgres BIND parsing can lead to a panic when malformed payloads are\n  processed (bsc#1267481).\n- CVE-2026-45682: go.opentelemetry.io/obi: keys not deleted by `CappedConcurrentHashMap` after removals allows repeated\n  connection churn to grow the queue without bound and exhaust heap memory (bsc#1267485).\n- CVE-2026-45685: go.opentelemetry.io/obi: MongoDB TCP parser panics on malformed wire messages and causes a DoS\n  (bsc#1267488).\n- CVE-2026-45686: go.opentelemetry.io/obi: integer overflow in memcached text protocol parser can crash the OBI process\n  and cause denial of service (bsc#1267489).\n- CVE-2026-46595: golang.org/x/crypto/ssh: source-address validation is skipped if any other type of callback is passed\n  other than public key (bsc#1266196).\n- CVE-2026-46597: golang.org/x/crypto/ssh: incorrectly placed cast from bytes to int in the AES-GCM packet decoder when\n  processing specially crafted input can lead to for server-side panic (bsc#1266196).\n- CVE-2026-46598: golang.org/x/crypto/ssh: `ed25519.PrivateKey` created by casting malformed wire bytes due to\n  processing of certain crafted inputs can lead to panic when used (bsc#1266196).\n\nOther updates and bugfixes:\n\n- Version 1.17.0:\n  * Features\n    * Add GraphQL server and `gql` subcommand.\n    * `otelcol`: Add Nginx receiver.\n    * `otelcol.exporter.prometheus`: Convert classic histograms to NHCB.\n    * `database_observability`: Various enhancements for MySQL and Postgres.\n    * `faro.receiver`: Support gzip-compressed request bodies.\n    * Update to Beyla 3.9.8.\n * Bug Fixes\n   * security: Update `x/crypto`, `x/net`, `jackc/pgx/v5`, and `obi`.\n   * cluster: Fix nodes failing to join the cluster with TLS enabled.\n   * `loki.process`: Fix potential deadlocks and limit stage shutdown.\n   * Update Go to v1.26.4.\n- Version 1.16.3:\n  * cluster: Fix nodes failing to join the cluster when TLS is enabled.\n- Version 1.16.2:\n  * `loki.process`: No longer mutate rules in `stage.truncate` causing every config update to reload pipeline when this\n    stage is used.\n  * `loki.process`: Potential deadlock on update with stage and receiver changes.\n  * `otelcol.exporter.awss3`: Add missing `unique_key_func_name` attribute.\n- Remove dependency on vulnerable `yaml` library.\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64],{"_key":15},"CVE-2026-25680",{"_key":17},"CVE-2026-25681",{"_key":19},"CVE-2026-27136",{"_key":21},"CVE-2026-33532",{"_key":23},"CVE-2026-39821",{"_key":25},"CVE-2026-39827",{"_key":27},"CVE-2026-39828",{"_key":29},"CVE-2026-39829",{"_key":31},"CVE-2026-39830",{"_key":33},"CVE-2026-39831",{"_key":35},"CVE-2026-39832",{"_key":37},"CVE-2026-39833",{"_key":39},"CVE-2026-39834",{"_key":41},"CVE-2026-39835",{"_key":43},"CVE-2026-41889",{"_key":45},"CVE-2026-42502",{"_key":47},"CVE-2026-42506",{"_key":49},"CVE-2026-42508",{"_key":51},"CVE-2026-44740",{"_key":53},"CVE-2026-45678",{"_key":55},"CVE-2026-45682",{"_key":57},"CVE-2026-45685",{"_key":59},"CVE-2026-45686",{"_key":61},"CVE-2026-46595",{"_key":63},"CVE-2026-46597",{"_key":65},"CVE-2026-46598",[],[],[69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":51},{"_key":53},{"_key":55},{"_key":57},{"_key":59},{"_key":61},{"_key":63},{"_key":65},"2026-07-07T17:00:29Z","2026-07-09T10:00:11.376074072Z",{"cisa_kev":98,"cisa_ransomware":98,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[100,106,110,114,118,122,126,130,134,138,142,147,151,155,159,163,167,171,175,179,183,187,191,195,199,203,207,211,215,219,223,227,231,235,239,243],{"url":101,"sources":102,"tags":104},"https://bugzilla.suse.com/1260981",[103],"osv_opensuse",[105],"REPORT",{"url":107,"sources":108,"tags":109},"https://bugzilla.suse.com/1265440",[103],[105],{"url":111,"sources":112,"tags":113},"https://bugzilla.suse.com/1266196",[103],[105],{"url":115,"sources":116,"tags":117},"https://bugzilla.suse.com/1266654",[103],[105],{"url":119,"sources":120,"tags":121},"https://bugzilla.suse.com/1267185",[103],[105],{"url":123,"sources":124,"tags":125},"https://bugzilla.suse.com/1267333",[103],[105],{"url":127,"sources":128,"tags":129},"https://bugzilla.suse.com/1267481",[103],[105],{"url":131,"sources":132,"tags":133},"https://bugzilla.suse.com/1267485",[103],[105],{"url":135,"sources":136,"tags":137},"https://bugzilla.suse.com/1267488",[103],[105],{"url":139,"sources":140,"tags":141},"https://bugzilla.suse.com/1267489",[103],[105],{"url":143,"sources":144,"tags":145},"https://www.suse.com/security/cve/CVE-2026-25680",[103],[146],"WEB",{"url":148,"sources":149,"tags":150},"https://www.suse.com/security/cve/CVE-2026-25681",[103],[146],{"url":152,"sources":153,"tags":154},"https://www.suse.com/security/cve/CVE-2026-27136",[103],[146],{"url":156,"sources":157,"tags":158},"https://www.suse.com/security/cve/CVE-2026-33532",[103],[146],{"url":160,"sources":161,"tags":162},"https://www.suse.com/security/cve/CVE-2026-39821",[103],[146],{"url":164,"sources":165,"tags":166},"https://www.suse.com/security/cve/CVE-2026-39827",[103],[146],{"url":168,"sources":169,"tags":170},"https://www.suse.com/security/cve/CVE-2026-39828",[103],[146],{"url":172,"sources":173,"tags":174},"https://www.suse.com/security/cve/CVE-2026-39829",[103],[146],{"url":176,"sources":177,"tags":178},"https://www.suse.com/security/cve/CVE-2026-39830",[103],[146],{"url":180,"sources":181,"tags":182},"https://www.suse.com/security/cve/CVE-2026-39831",[103],[146],{"url":184,"sources":185,"tags":186},"https://www.suse.com/security/cve/CVE-2026-39832",[103],[146],{"url":188,"sources":189,"tags":190},"https://www.suse.com/security/cve/CVE-2026-39833",[103],[146],{"url":192,"sources":193,"tags":194},"https://www.suse.com/security/cve/CVE-2026-39834",[103],[146],{"url":196,"sources":197,"tags":198},"https://www.suse.com/security/cve/CVE-2026-39835",[103],[146],{"url":200,"sources":201,"tags":202},"https://www.suse.com/security/cve/CVE-2026-41889",[103],[146],{"url":204,"sources":205,"tags":206},"https://www.suse.com/security/cve/CVE-2026-42502",[103],[146],{"url":208,"sources":209,"tags":210},"https://www.suse.com/security/cve/CVE-2026-42506",[103],[146],{"url":212,"sources":213,"tags":214},"https://www.suse.com/security/cve/CVE-2026-42508",[103],[146],{"url":216,"sources":217,"tags":218},"https://www.suse.com/security/cve/CVE-2026-44740",[103],[146],{"url":220,"sources":221,"tags":222},"https://www.suse.com/security/cve/CVE-2026-45678",[103],[146],{"url":224,"sources":225,"tags":226},"https://www.suse.com/security/cve/CVE-2026-45682",[103],[146],{"url":228,"sources":229,"tags":230},"https://www.suse.com/security/cve/CVE-2026-45685",[103],[146],{"url":232,"sources":233,"tags":234},"https://www.suse.com/security/cve/CVE-2026-45686",[103],[146],{"url":236,"sources":237,"tags":238},"https://www.suse.com/security/cve/CVE-2026-46595",[103],[146],{"url":240,"sources":241,"tags":242},"https://www.suse.com/security/cve/CVE-2026-46597",[103],[146],{"url":244,"sources":245,"tags":246},"https://www.suse.com/security/cve/CVE-2026-46598",[103],[146],[],[],[],[251],{"ecosystem":252,"name":253,"vendor":254,"product":255,"cpe_part":9,"purl_type":256,"purl_namespace":254,"purl_name":255,"source":9,"versions":257},"openSUSE","alloy","opensuse","alloy&distro=openSUSE Leap 16.0","rpm",[258],{"version":259,"is_range":260,"range_type":261,"version_start":9,"version_start_type":9,"version_end":262,"version_end_type":263,"fixed_in":9},"lt1_17_0_160000_1_1",true,"ecosystem","1.17.0-160000.1.1","excluding"]