[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:21481-1":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T11:35:27.363Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":32,"duplicates":33,"related":34,"reserved_at":9,"published_at":44,"modified_at":45,"state":9,"summary":46,"references_raw":48,"kevs":124,"epss":9,"epss_history":125,"metrics":126,"affected":127},"OPENSUSE-SU-2026:21481-1","Security update for vexctl\n\nThis update for vexctl fixes the following issues:\n\n- CVE-2024-45337: golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in\n  golang.org/x/crypto (bsc#1234486).\n- CVE-2025-22868: golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2\n  (bsc#1239186).\n- CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh\n  (bsc#1239323).\n- CVE-2025-22870: golang.org/x/net/proxy: proxy bypass using IPv6 zone IDs (bsc#1238683).\n- CVE-2025-27144: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: Go JOSE's Parsing Vulnerable to Denial of\n  Service (bsc#1237611).\n- CVE-2025-30204: github.com/golang-jwt/jwt/v4: jwt-go allows excessive memory allocation during header parsing\n  (bsc#1240444).\n- CVE-2025-58181: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption\n  (bsc#1253802).\n- CVE-2026-22772: github.com/sigstore/fulcio: bypass MetaIssuer URL validation bypass can trigger SSRF to arbitrary\n  internal services (bsc#1256535).\n- CVE-2026-24137: github.com/sigstore/sigstore/pkg/tuf: legacy TUF client allows for arbitrary file writes with target\n  cache path traversal (bsc#1257138).\n\nChanges for vexctl:\n\n- Update to version 0.4.4+git20.5d61136:\n\n * build(deps): Bump github.com/sigstore/cosign/v2\n * build(deps): Bump actions/setup-go from 6.5.0 to 7.0.0\n * build(deps): Bump the all group across 1 directory with 5 updates\n * build(deps): Bump github.com/sigstore/rekor in the all group\n * build(deps): Bump the all group with 4 updates\n * build(deps): Bump github.com/google/go-containerregistry\n * build(deps): Bump actions/setup-go from 6.4.0 to 6.5.0 in the all group\n * build(deps): Bump the all group across 1 directory with 2 updates\n * build(deps): Bump actions/checkout from 6.0.3 to 7.0.0\n * build(deps): Bump chainguard-dev/actions in the all group\n\n- Update to version 0.4.4:\n\n * fix signature duplication\n * fix lints\n * housekeeping - deps update and ci cleanup\n * build(deps): Bump the all group with 2 updates\n * build(deps): Bump github.com/sigstore/sigstore in the all group\n * build(deps): Bump golangci/golangci-lint-action in the all group\n\n- Update to version 0.4.1+git147.b7e6ef0:\n\n * build(deps): Bump goreleaser/goreleaser-action in the all group\n * Bump sigstore/cosign-installer from 4.1.1 to 4.1.2 in the all group\n * Bump chainguard-dev/actions from 1.6.17 to 1.6.19 in the all group\n * Bump chainguard-dev/actions from 1.6.16 to 1.6.17 in the all group\n * Bump github.com/package-url/packageurl-go in the all group\n * Bump the all group with 2 updates\n\n- Update to version 0.4.1+git133.efecaf7:\n\n * Bump github.com/secure-systems-lab/go-securesystemslib\n\n- Update to version 0.4.1+git129.c7f3066:\n\n * Bump github.com/google/go-containerregistry in the all group\n * Bump github.com/sigstore/timestamp-authority/v2 from 2.0.3 to 2.0.6\n * Bump softprops/action-gh-release from 2.6.1 to 3.0.0\n * Bump chainguard-dev/actions from 1.6.13 to 1.6.14 in the all group\n * Bump actions/upload-artifact from 7.0.0 to 7.0.1 in the all group\n * Bump github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3 in the all group\n * Bump kubernetes-sigs/release-actions in the all group\n * Bump github.com/in-toto/in-toto-golang from 0.9.0 to 0.10.0\n * Bump the all group across 1 directory with 2 updates\n * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4\n * fix(add): allow add without --product flag\n * Use gomod version, bump linter\n * Port vexctl to intoto/attestation\n * Bump the all group across 1 directory with 5 updates\n * Bump google.golang.org/grpc from 1.78.0 to 1.79.3\n\n- Update to version 0.4.1+git96.558125d:\n\n * Bump the all group across 1 directory with 3 updates\n * Bump chainguard-dev/actions from 1.6.5 to 1.6.6 in the all group\n * Bump github.com/google/go-containerregistry from 0.20.7 to 0.21.0\n * Bump actions/upload-artifact from 6.0.0 to 7.0.0\n * Bump goreleaser/goreleaser-action from 6.4.0 to 7.0.0\n * Bump chainguard-dev/actions from 1.6.2 to 1.6.4 in the all group\n\n- Update to version 0.4.1+git78.f951e3a:\n\n * Bump chainguard-dev/actions from 1.6.1 to 1.6.2 in the all group\n\n- Update to version 0.4.1+git76.10d7a2e:\n\n * Bump chainguard-dev/actions from 1.6.0 to 1.6.1 in the all group\n * Bump chainguard-dev/actions from 1.5.16 to 1.6.0 in the all group\n * Bump chainguard-dev/actions from 1.5.14 to 1.5.16 in the all group\n * Bump chainguard-dev/actions from 1.5.13 to 1.5.14 in the all group\n * Bump github.com/sigstore/rekor from 1.4.3 to 1.5.0\n * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to 2.4.1\n * Bump actions/setup-go from 6.1.0 to 6.2.0 in the all group\n * Bump github.com/sigstore/fulcio from 1.8.4 to 1.8.5\n * Bump github.com/sigstore/cosign/v2 from 2.6.1 to 2.6.2 in the all group\n * Bump chainguard-dev/actions from 1.5.10 to 1.5.11 in the all group\n * Bump github.com/sigstore/fulcio from 1.7.1 to 1.8.3\n * Bump github.com/sigstore/sigstore\n * Bump actions/upload-artifact from 5.0.0 to 6.0.0\n * bump golangci-lint\n * update gorelease sing to works with cosign 3.0+\n * Bump github.com/spf13/cobra from 1.10.1 to 1.10.2 in the all group\n * Bump golangci/golangci-lint-action from 9.1.0 to 9.2.0 in the all group\n * Bump actions/checkout from 6.0.0 to 6.0.1 in the all group\n * Bump softprops/action-gh-release from 2.4.2 to 2.5.0 in the all group\n * Bump chainguard-dev/actions from 1.5.9 to 1.5.10 in the all group\n * Bump golangci/golangci-lint-action from 8.0.0 to 9.1.0\n * Bump actions/checkout from 5.0.1 to 6.0.0\n * Bump actions/setup-go from 6.0.0 to 6.1.0 in the all group\n * Bump golang.org/x/crypto from 0.43.0 to 0.45.0\n * Bump github.com/sigstore/rekor from 1.4.2 to 1.4.3 in the all group\n * Bump actions/upload-artifact from 4.6.2 to 5.0.0\n * Bump chainguard-dev/actions from 1.5.6 to 1.5.7 in the all group\n * Bump sigstore/cosign-installer from 3.10.0 to 4.0.0\n * Bump chainguard-dev/actions from 1.5.4 to 1.5.6 in the all group\n * Bump softprops/action-gh-release from 2.3.4 to 2.4.0 in the all group\n * Bump github.com/sigstore/cosign/v2 from 2.6.0 to 2.6.1 in the all group\n\n- Update to version 0.4.1:\n\n * Reverse platform+os naming scheme\n\n- Update to version 0.4.0:\n\n * update go, goreleaser and update/clean ci\n * Bump sigs.k8s.io/release-utils from 0.12.1 to 0.12.2 in the all group\n\n- Packaging improvements:\n\n * Update to BuildRequires: golang(API) >= 1.25 matching go.mod\n\n- Update to version 0.3.0+git181.33bac59:\n\n * Bump sigstore/cosign-installer from 3.9.2 to 3.10.0 in the all group\n * Fix break w/cosign 2.6.0\n * Bump cosign & go-vex\n * Fix 2.4 linter nits\n * Bump softprops/action-gh-release from 2.3.2 to 2.3.3 in the all group\n * Bump github.com/spf13/cobra from 1.9.1 to 1.10.1\n * Bump actions/setup-go from 5.5.0 to 6.0.0\n * Bump github.com/stretchr/testify from 1.11.0 to 1.11.1 in the all group\n * Bump github.com/stretchr/testify from 1.10.0 to 1.11.0\n * Bump github.com/go-viper/mapstructure/v2 in the go_modules group\n * Bump goreleaser/goreleaser-action from 6.3.0 to 6.4.0 in the all group\n * update release-utils and fix pkg name\n * Bump actions/checkout from 4.2.2 to 5.0.0\n * Bump github.com/secure-systems-lab/go-securesystemslib in the all group\n * Bump github.com/sigstore/rekor from 1.3.10 to 1.4.0\n * Bump sigs.k8s.io/release-utils from 0.11.1 to 0.12.0\n * Bump sigstore/cosign-installer from 3.9.1 to 3.9.2 in the all group\n * Bump github.com/sigstore/cosign/v2 from 2.5.2 to 2.5.3 in the all group\n * Bump sigstore/cosign-installer from 3.9.0 to 3.9.1 in the all group\n * Bump github.com/sigstore/cosign/v2 from 2.5.1 to 2.5.2 in the all group\n * Bump sigstore/cosign-installer from 3.8.2 to 3.9.0 in the all group\n * migrate config to v2\n * Bump golangci/golangci-lint-action from 6.5.2 to 8.0.0\n\n- Update to version 0.3.0+git133.ff97560:\n\n * Bump softprops/action-gh-release from 2.3.0 to 2.3.2 in the all group\n * Bump github.com/cloudflare/circl in the go_modules group\n * Bump softprops/action-gh-release from 2.2.2 to 2.3.0 in the all group\n * Bump actions/setup-go from 5.4.0 to 5.5.0 in the all group\n * Bump github.com/sigstore/sigstore from 1.9.3 to 1.9.4 in the all group\n * Bump sigstore/cosign-installer from 3.8.1 to 3.8.2 in the all group\n * Bump softprops/action-gh-release from 2.2.1 to 2.2.2 in the all group\n * Bump ko-build/setup-ko from 0.8 to 0.9 in the all group\n * Bump github.com/sigstore/cosign/v2 from 2.4.3 to 2.5.0\n * Bump goreleaser/goreleaser-action from 6.2.1 to 6.3.0 in the all group\n * Bump sigs.k8s.io/release-utils from 0.11.0 to 0.11.1 in the all group\n * Bump github.com/golang-jwt/jwt/v4 in the go_modules group\n * Bump golangci/golangci-lint-action from 6.5.1 to 6.5.2 in the all group\n * Bump github.com/sigstore/sigstore from 1.8.15 to 1.9.1\n * Bump golang.org/x/net from 0.35.0 to 0.36.0 in the go_modules group\n * Bump golangci/golangci-lint-action from 6.5.0 to 6.5.1 in the all group\n * Bump github.com/go-jose/go-jose/v3 in the go_modules group\n * Bump github.com/go-jose/go-jose/v4 in the go_modules group\n * Bump actions/upload-artifact from 4.6.0 to 4.6.1 in the all group\n * Bump sigstore/cosign-installer from 3.8.0 to 3.8.1 in the all group\n * use go1.24 and update golangci-lint\n * Bump golangci/golangci-lint-action from 6.3.3 to 6.5.0 in the all group\n * Bump github.com/spf13/cobra from 1.8.1 to 1.9.1\n * Bump github.com/sigstore/sigstore from 1.8.12 to 1.8.14 in the all group\n * Bump golangci/golangci-lint-action from 6.3.2 to 6.3.3 in the all group\n * Bump goreleaser/goreleaser-action from 6.1.0 to 6.2.1 in the all group\n * Bump golangci/golangci-lint-action from 6.3.0 to 6.3.2 in the all group\n * Bump sigstore/cosign-installer from 3.7.0 to 3.8.0 in the all group\n * Bump golangci/golangci-lint-action from 6.2.0 to 6.3.0 in the all group\n * Bump sigs.k8s.io/release-utils from 0.9.0 to 0.10.0\n * Bump github.com/sigstore/rekor from 1.3.8 to 1.3.9 in the all group\n * Bump actions/setup-go from 5.2.0 to 5.3.0 in the all group\n * Bump golangci/golangci-lint-action from 6.1.1 to 6.2.0 in the all group\n * Bump sigs.k8s.io/release-utils from 0.8.5 to 0.9.0\n * Bump go dependencies manually\n * Bump ko-build/setup-ko from 0.7 to 0.8 in the all group\n * Bump actions/upload-artifact from 4.5.0 to 4.6.0 in the all group\n * Bump softprops/action-gh-release from 2.2.0 to 2.2.1 in the all group\n * Bump actions/upload-artifact from 4.4.3 to 4.5.0 in the all group\n * Bump golang.org/x/crypto from 0.28.0 to 0.31.0 in the go_modules group\n * Bump softprops/action-gh-release from 2.0.9 to 2.1.0 in the all group\n * Bump goreleaser/goreleaser-action from 6.0.0 to 6.1.0 in the all group\n * Bump softprops/action-gh-release from 2.0.8 to 2.0.9 in the all group\n * Update verify.yaml\n * Update release.yaml\n * Update ci-build-test.yaml\n * Bump actions/setup-go from 5.0.2 to 5.1.0 in the all group\n * Bump actions/checkout from 4.2.1 to 4.2.2 in the all group\n * Bump github.com/sigstore/sigstore from 1.8.9 to 1.8.10 in the all group\n * Bump actions/upload-artifact from 4.4.2 to 4.4.3 in the all group\n * Bump actions/upload-artifact from 4.4.1 to 4.4.2 in the all group\n * Bump sigstore/cosign-installer from 3.6.0 to 3.7.0 in the all group\n * Bump golangci/golangci-lint-action from 6.1.0 to 6.1.1 in the all group\n * Bump github.com/sigstore/cosign/v2 from 2.4.0 to 2.4.1 in the all group\n * Bump actions/checkout from 4.1.7 to 4.2.0 in the all group\n * Bump sigs.k8s.io/release-utils from 0.8.4 to 0.8.5 in the all group\n * upgrade to go1.23\n",null,[],[],[],[14,16,18,20,22,24,26,28,30],{"_key":15},"CVE-2024-45337",{"_key":17},"CVE-2025-22868",{"_key":19},"CVE-2025-22869",{"_key":21},"CVE-2025-22870",{"_key":23},"CVE-2025-27144",{"_key":25},"CVE-2025-30204",{"_key":27},"CVE-2025-58181",{"_key":29},"CVE-2026-22772",{"_key":31},"CVE-2026-24137",[],[],[35,36,37,38,39,40,41,42,43],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},"2026-07-30T04:41:29Z","2026-07-31T18:24:08.134854039Z",{"cisa_kev":47,"cisa_ransomware":47,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[49,55,59,63,67,71,75,79,83,87,92,96,100,104,108,112,116,120],{"url":50,"sources":51,"tags":53},"https://bugzilla.suse.com/1234486",[52],"osv_opensuse",[54],"REPORT",{"url":56,"sources":57,"tags":58},"https://bugzilla.suse.com/1237611",[52],[54],{"url":60,"sources":61,"tags":62},"https://bugzilla.suse.com/1238683",[52],[54],{"url":64,"sources":65,"tags":66},"https://bugzilla.suse.com/1239186",[52],[54],{"url":68,"sources":69,"tags":70},"https://bugzilla.suse.com/1239323",[52],[54],{"url":72,"sources":73,"tags":74},"https://bugzilla.suse.com/1240444",[52],[54],{"url":76,"sources":77,"tags":78},"https://bugzilla.suse.com/1253802",[52],[54],{"url":80,"sources":81,"tags":82},"https://bugzilla.suse.com/1256535",[52],[54],{"url":84,"sources":85,"tags":86},"https://bugzilla.suse.com/1257138",[52],[54],{"url":88,"sources":89,"tags":90},"https://www.suse.com/security/cve/CVE-2024-45337",[52],[91],"WEB",{"url":93,"sources":94,"tags":95},"https://www.suse.com/security/cve/CVE-2025-22868",[52],[91],{"url":97,"sources":98,"tags":99},"https://www.suse.com/security/cve/CVE-2025-22869",[52],[91],{"url":101,"sources":102,"tags":103},"https://www.suse.com/security/cve/CVE-2025-22870",[52],[91],{"url":105,"sources":106,"tags":107},"https://www.suse.com/security/cve/CVE-2025-27144",[52],[91],{"url":109,"sources":110,"tags":111},"https://www.suse.com/security/cve/CVE-2025-30204",[52],[91],{"url":113,"sources":114,"tags":115},"https://www.suse.com/security/cve/CVE-2025-58181",[52],[91],{"url":117,"sources":118,"tags":119},"https://www.suse.com/security/cve/CVE-2026-22772",[52],[91],{"url":121,"sources":122,"tags":123},"https://www.suse.com/security/cve/CVE-2026-24137",[52],[91],[],[],[],[128],{"ecosystem":129,"name":130,"vendor":131,"product":132,"cpe_part":9,"purl_type":133,"purl_namespace":131,"purl_name":132,"source":9,"versions":134},"openSUSE","vexctl","opensuse","vexctl&distro=openSUSE Leap 16.0","rpm",[135],{"version":136,"is_range":137,"range_type":138,"version_start":9,"version_start_type":9,"version_end":139,"version_end_type":140,"fixed_in":9},"lt0_4_4+git20_5d61136_160000_1_1",true,"ecosystem","0.4.4+git20.5d61136-160000.1.1","excluding"]