[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:21319-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-07-31T17:19:26.604Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":74,"duplicates":75,"related":76,"reserved_at":9,"published_at":107,"modified_at":108,"state":9,"summary":109,"references_raw":111,"kevs":371,"epss":9,"epss_history":372,"metrics":373,"affected":374},"OPENSUSE-SU-2026:21319-1","Security update for go1.25-openssl\n\nThis update for go1.25-openssl fixes the following issues\n\n- Update to version go1.25.12 (bsc#1244485).\n- CVE-2025-61732: cmd/cgo: discrepancy between Go and C/C++ comment parsing allows for C code smuggling (bsc#1257692).\n- CVE-2025-68121: crypto/tls: Config.Clone copies automatically generated session ticket keys, session resumption does not account for the expiration of full certificate chain (bsc#1256818).\n- CVE-2026-25679: net/url: reject IPv6 literal not at start of host (bsc#1259264).\n- CVE-2026-27139: os: FileInfo can escape from a Root (bsc#1259268).\n- CVE-2026-27140: cmd/go: trust layer bypass when using cgo and SWIG (bsc#1261653).\n- CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped (bsc#1259265).\n- CVE-2026-27143: cmd/compile: possible memory corruption after bound check elimination (bsc#1261654).\n- CVE-2026-27144: cmd/compile: no-op interface conversion bypasses overlap checking (bsc#1261655).\n- CVE-2026-27145: crypto/x509: split candidate hostname only once (bsc#1267450).\n- CVE-2026-32280: crypto/x509: unexpected work during chain building (bsc#1261656).\n- CVE-2026-32281: crypto/x509: inefficient policy validation (bsc#1261657).\n- CVE-2026-32282: os: Root.Chmod can follow symlinks out of the root on Linux (bsc#1261658).\n- CVE-2026-32283: crypto/tls: multiple key update handshake messages can cause connection to deadlock (bsc#1261659).\n- CVE-2026-32288: archive/tar: unbounded allocation when parsing old format GNU sparse map (bsc#1261660).\n- CVE-2026-32289: html/template: JS template literal context incorrectly tracked (bsc#1261661).\n- CVE-2026-33811: net: crash when handling long CNAME response (bsc#1264508).\n- CVE-2026-33814: net/http: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1264506).\n- CVE-2026-39817: cmd/go: \"go tool pack\" does not sanitize output paths (bsc#1264505).\n- CVE-2026-39819: cmd/go: \"go bug\" follows symlinks in predictable temporary filenames (bsc#1264504).\n- CVE-2026-39820: net/mail: quadratic string concatentation in consumeComment (bsc#1264503).\n- CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014).\n- CVE-2026-39823: html/template: bypass of meta content URL escaping causes XSS (bsc#1264509).\n- CVE-2026-39825: net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters (bsc#1264500).\n- CVE-2026-39826: html/template: escaper bypass leads to XSS (bsc#1264507).\n- CVE-2026-39836: net: panic in Dial and LookupPort when handling NUL byte on Windows (bsc#1264501).\n- CVE-2026-42499: net/mail: quadratic string concatenation in consumePhrase (bsc#1264502).\n- CVE-2026-42501: cmd/go: malicious module proxy can bypass checksum database (bsc#1264499).\n- CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader (bsc#1267442).\n- CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015).\n- CVE-2026-42507: net/textproto: arbitrary input are included in errors without any escaping (bsc#1267444).\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64,66,68,70,72],{"_key":15},"CVE-2025-61732",{"_key":17},"CVE-2025-68121",{"_key":19},"CVE-2026-25679",{"_key":21},"CVE-2026-27139",{"_key":23},"CVE-2026-27140",{"_key":25},"CVE-2026-27142",{"_key":27},"CVE-2026-27143",{"_key":29},"CVE-2026-27144",{"_key":31},"CVE-2026-27145",{"_key":33},"CVE-2026-32280",{"_key":35},"CVE-2026-32281",{"_key":37},"CVE-2026-32282",{"_key":39},"CVE-2026-32283",{"_key":41},"CVE-2026-32288",{"_key":43},"CVE-2026-32289",{"_key":45},"CVE-2026-33811",{"_key":47},"CVE-2026-33814",{"_key":49},"CVE-2026-39817",{"_key":51},"CVE-2026-39819",{"_key":53},"CVE-2026-39820",{"_key":55},"CVE-2026-39822",{"_key":57},"CVE-2026-39823",{"_key":59},"CVE-2026-39825",{"_key":61},"CVE-2026-39826",{"_key":63},"CVE-2026-39836",{"_key":65},"CVE-2026-42499",{"_key":67},"CVE-2026-42501",{"_key":69},"CVE-2026-42504",{"_key":71},"CVE-2026-42505",{"_key":73},"CVE-2026-42507",[],[],[77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":51},{"_key":53},{"_key":55},{"_key":57},{"_key":59},{"_key":61},{"_key":63},{"_key":65},{"_key":67},{"_key":69},{"_key":71},{"_key":73},"2026-07-13T12:46:24Z","2026-07-15T18:24:13.471492725Z",{"cisa_kev":110,"cisa_ransomware":110,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[112,118,122,126,130,134,138,142,146,150,154,158,162,166,170,174,178,182,186,190,194,198,202,206,210,214,218,222,226,230,234,238,242,246,250,255,259,263,267,271,275,279,283,287,291,295,299,303,307,311,315,319,323,327,331,335,339,343,347,351,355,359,363,367],{"url":113,"sources":114,"tags":116},"https://bugzilla.suse.com/1170826",[115],"osv_opensuse",[117],"REPORT",{"url":119,"sources":120,"tags":121},"https://bugzilla.suse.com/1244485",[115],[117],{"url":123,"sources":124,"tags":125},"https://bugzilla.suse.com/1245878",[115],[117],{"url":127,"sources":128,"tags":129},"https://bugzilla.suse.com/1256818",[115],[117],{"url":131,"sources":132,"tags":133},"https://bugzilla.suse.com/1257692",[115],[117],{"url":135,"sources":136,"tags":137},"https://bugzilla.suse.com/1259264",[115],[117],{"url":139,"sources":140,"tags":141},"https://bugzilla.suse.com/1259265",[115],[117],{"url":143,"sources":144,"tags":145},"https://bugzilla.suse.com/1259268",[115],[117],{"url":147,"sources":148,"tags":149},"https://bugzilla.suse.com/1261653",[115],[117],{"url":151,"sources":152,"tags":153},"https://bugzilla.suse.com/1261654",[115],[117],{"url":155,"sources":156,"tags":157},"https://bugzilla.suse.com/1261655",[115],[117],{"url":159,"sources":160,"tags":161},"https://bugzilla.suse.com/1261656",[115],[117],{"url":163,"sources":164,"tags":165},"https://bugzilla.suse.com/1261657",[115],[117],{"url":167,"sources":168,"tags":169},"https://bugzilla.suse.com/1261658",[115],[117],{"url":171,"sources":172,"tags":173},"https://bugzilla.suse.com/1261659",[115],[117],{"url":175,"sources":176,"tags":177},"https://bugzilla.suse.com/1261660",[115],[117],{"url":179,"sources":180,"tags":181},"https://bugzilla.suse.com/1261661",[115],[117],{"url":183,"sources":184,"tags":185},"https://bugzilla.suse.com/1264394",[115],[117],{"url":187,"sources":188,"tags":189},"https://bugzilla.suse.com/1264499",[115],[117],{"url":191,"sources":192,"tags":193},"https://bugzilla.suse.com/1264500",[115],[117],{"url":195,"sources":196,"tags":197},"https://bugzilla.suse.com/1264501",[115],[117],{"url":199,"sources":200,"tags":201},"https://bugzilla.suse.com/1264502",[115],[117],{"url":203,"sources":204,"tags":205},"https://bugzilla.suse.com/1264503",[115],[117],{"url":207,"sources":208,"tags":209},"https://bugzilla.suse.com/1264504",[115],[117],{"url":211,"sources":212,"tags":213},"https://bugzilla.suse.com/1264505",[115],[117],{"url":215,"sources":216,"tags":217},"https://bugzilla.suse.com/1264506",[115],[117],{"url":219,"sources":220,"tags":221},"https://bugzilla.suse.com/1264507",[115],[117],{"url":223,"sources":224,"tags":225},"https://bugzilla.suse.com/1264508",[115],[117],{"url":227,"sources":228,"tags":229},"https://bugzilla.suse.com/1264509",[115],[117],{"url":231,"sources":232,"tags":233},"https://bugzilla.suse.com/1267442",[115],[117],{"url":235,"sources":236,"tags":237},"https://bugzilla.suse.com/1267444",[115],[117],{"url":239,"sources":240,"tags":241},"https://bugzilla.suse.com/1267450",[115],[117],{"url":243,"sources":244,"tags":245},"https://bugzilla.suse.com/1271014",[115],[117],{"url":247,"sources":248,"tags":249},"https://bugzilla.suse.com/1271015",[115],[117],{"url":251,"sources":252,"tags":253},"https://www.suse.com/security/cve/CVE-2025-61732",[115],[254],"WEB",{"url":256,"sources":257,"tags":258},"https://www.suse.com/security/cve/CVE-2025-68121",[115],[254],{"url":260,"sources":261,"tags":262},"https://www.suse.com/security/cve/CVE-2026-25679",[115],[254],{"url":264,"sources":265,"tags":266},"https://www.suse.com/security/cve/CVE-2026-27139",[115],[254],{"url":268,"sources":269,"tags":270},"https://www.suse.com/security/cve/CVE-2026-27140",[115],[254],{"url":272,"sources":273,"tags":274},"https://www.suse.com/security/cve/CVE-2026-27142",[115],[254],{"url":276,"sources":277,"tags":278},"https://www.suse.com/security/cve/CVE-2026-27143",[115],[254],{"url":280,"sources":281,"tags":282},"https://www.suse.com/security/cve/CVE-2026-27144",[115],[254],{"url":284,"sources":285,"tags":286},"https://www.suse.com/security/cve/CVE-2026-27145",[115],[254],{"url":288,"sources":289,"tags":290},"https://www.suse.com/security/cve/CVE-2026-32280",[115],[254],{"url":292,"sources":293,"tags":294},"https://www.suse.com/security/cve/CVE-2026-32281",[115],[254],{"url":296,"sources":297,"tags":298},"https://www.suse.com/security/cve/CVE-2026-32282",[115],[254],{"url":300,"sources":301,"tags":302},"https://www.suse.com/security/cve/CVE-2026-32283",[115],[254],{"url":304,"sources":305,"tags":306},"https://www.suse.com/security/cve/CVE-2026-32288",[115],[254],{"url":308,"sources":309,"tags":310},"https://www.suse.com/security/cve/CVE-2026-32289",[115],[254],{"url":312,"sources":313,"tags":314},"https://www.suse.com/security/cve/CVE-2026-33811",[115],[254],{"url":316,"sources":317,"tags":318},"https://www.suse.com/security/cve/CVE-2026-33814",[115],[254],{"url":320,"sources":321,"tags":322},"https://www.suse.com/security/cve/CVE-2026-39817",[115],[254],{"url":324,"sources":325,"tags":326},"https://www.suse.com/security/cve/CVE-2026-39819",[115],[254],{"url":328,"sources":329,"tags":330},"https://www.suse.com/security/cve/CVE-2026-39820",[115],[254],{"url":332,"sources":333,"tags":334},"https://www.suse.com/security/cve/CVE-2026-39822",[115],[254],{"url":336,"sources":337,"tags":338},"https://www.suse.com/security/cve/CVE-2026-39823",[115],[254],{"url":340,"sources":341,"tags":342},"https://www.suse.com/security/cve/CVE-2026-39825",[115],[254],{"url":344,"sources":345,"tags":346},"https://www.suse.com/security/cve/CVE-2026-39826",[115],[254],{"url":348,"sources":349,"tags":350},"https://www.suse.com/security/cve/CVE-2026-39836",[115],[254],{"url":352,"sources":353,"tags":354},"https://www.suse.com/security/cve/CVE-2026-42499",[115],[254],{"url":356,"sources":357,"tags":358},"https://www.suse.com/security/cve/CVE-2026-42501",[115],[254],{"url":360,"sources":361,"tags":362},"https://www.suse.com/security/cve/CVE-2026-42504",[115],[254],{"url":364,"sources":365,"tags":366},"https://www.suse.com/security/cve/CVE-2026-42505",[115],[254],{"url":368,"sources":369,"tags":370},"https://www.suse.com/security/cve/CVE-2026-42507",[115],[254],[],[],[],[375],{"ecosystem":376,"name":377,"vendor":378,"product":379,"cpe_part":9,"purl_type":380,"purl_namespace":378,"purl_name":379,"source":9,"versions":381},"openSUSE","go1.25-openssl","opensuse","go1.25-openssl&distro=openSUSE Leap 16.0","rpm",[382],{"version":383,"is_range":384,"range_type":385,"version_start":9,"version_start_type":9,"version_end":386,"version_end_type":387,"fixed_in":9},"lt1_25_12_160000_1_1",true,"ecosystem","1.25.12-160000.1.1","excluding"]