[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-SUSE-SU-2026:22575-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-01T00:21:03.480Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":66,"duplicates":67,"related":68,"reserved_at":9,"published_at":95,"modified_at":96,"state":9,"summary":97,"references_raw":99,"kevs":252,"epss":9,"epss_history":253,"metrics":254,"affected":255},"SUSE-SU-2026:22575-1","Security update for alloy\n\nThis update for alloy fixes the following issues:\n\nUpdate to version 1.17.0.\n\nSecurity issues fixed:\n\n- CVE-2026-25680: golang.org/x/net/html: parsing arbitrary HTML can consume excessive CPU time, possibly leading to\n  denial of service (bsc#1267185).\n- CVE-2026-25681: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an\n  unexpected HTML tree and allows for XSS (bsc#1267185).\n- CVE-2026-27136: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an\n  unexpected HTML tree and allows for XSS (bsc#1267185).\n- CVE-2026-33532: yaml: parsing input with deeply nestes collections may throw a `RangeError` due to a stack overflow\n  and cause to a denial of service (bsc#1260981).\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation\n  bypass and privilege escalation (bsc#1266654).\n- CVE-2026-39827: golang.org/x/crypto/ssh: authenticated SSH clients that repeatedly open channels which were rejected\n  by the server can cause unbounded memory growth and a crash (bsc#1266196).\n- CVE-2026-39828: golang.org/x/crypto/ssh: permissions discarded when an SSH server authentication callback returns\n  `PartialSuccessError` with non-`nil` permissions (bsc#1266196).\n- CVE-2026-39829: golang.org/x/crypto/ssh: unenforced size limits on key parameters by the the RSA and DSA public key\n  parsers can lead to excessive CPU consumption when processing a crafted public key (bsc#1266196).\n- CVE-2026-39830: golang.org/x/crypto/ssh: malicious SSH peers sending unsolicited global request responses can block a\n  connection's read loop and cause a resource leak (bsc#1266196).\n- CVE-2026-39831: golang.org/x/crypto/ssh: missing `User Presence` flag checks in the `Verify()` method for FIDO/U2F\n  security key types cause signatures generated without physical touch to be accepted (bsc#1266196).\n- CVE-2026-39832: golang.org/x/crypto/ssh: destination restrictions are silently stripped when forwarding keys and\n  allow for unrestricted use of a key on a remote host (bsc#1266196).\n- CVE-2026-39833: golang.org/x/crypto/ssh: in-memory keyring returned by `NewKeyring()` silently accepts keys with the\n  `ConfirmBeforeUse` constraint but never enforces it (bsc#1266196).\n- CVE-2026-39834: golang.org/x/crypto/ssh: writing data larger than 4GB in a single `Write` call on an SSH channel\n  leads to an integer overflow and an infinite loop that sends empty packets (bsc#1266196).\n- CVE-2026-39835: golang.org/x/crypto/ssh: processing of certificates by SSH servers using `CertChecker` as a public\n  key callback without setting `IsUserAuthority` or `IsHostAuthority` can lead to a panic (bsc#1266196).\n- CVE-2026-41889: github.com/jackc/pgx/v5/internal/sanitize: use placeholders in dollar-quoted string literals in an\n  SQL query can lead to a SQL injection (bsc#1265440).\n- CVE-2026-42502: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an\n  unexpected HTML tree and allows for XSS (bsc#1267185).\n- CVE-2026-42506: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an\n  unexpected HTML tree and allows for XSS (bsc#1267185).\n- CVE-2026-42508: golang.org/x/crypto/ssh: revoked `SignatureKey`s belonging to a CA are not correctly checked for\n  revocation (bsc#1266196).\n- CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via\n  infinite loops, panics or resource consumption (bsc#1267333).\n- CVE-2026-45678: go.opentelemetry.io/obi: Postgres BIND parsing can lead to a panic when malformed payloads are\n  processed (bsc#1267481).\n- CVE-2026-45682: go.opentelemetry.io/obi: keys not deleted by `CappedConcurrentHashMap` after removals allows repeated\n  connection churn to grow the queue without bound and exhaust heap memory (bsc#1267485).\n- CVE-2026-45685: go.opentelemetry.io/obi: MongoDB TCP parser panics on malformed wire messages and causes a DoS\n  (bsc#1267488).\n- CVE-2026-45686: go.opentelemetry.io/obi: integer overflow in memcached text protocol parser can crash the OBI process\n  and cause denial of service (bsc#1267489).\n- CVE-2026-46595: golang.org/x/crypto/ssh: source-address validation is skipped if any other type of callback is passed\n  other than public key (bsc#1266196).\n- CVE-2026-46597: golang.org/x/crypto/ssh: incorrectly placed cast from bytes to int in the AES-GCM packet decoder when\n  processing specially crafted input can lead to for server-side panic (bsc#1266196).\n- CVE-2026-46598: golang.org/x/crypto/ssh: `ed25519.PrivateKey` created by casting malformed wire bytes due to\n  processing of certain crafted inputs can lead to panic when used (bsc#1266196).\n\nOther updates and bugfixes:\n\n- Version 1.17.0:\n  * Features\n    * Add GraphQL server and `gql` subcommand.\n    * `otelcol`: Add Nginx receiver.\n    * `otelcol.exporter.prometheus`: Convert classic histograms to NHCB.\n    * `database_observability`: Various enhancements for MySQL and Postgres.\n    * `faro.receiver`: Support gzip-compressed request bodies.\n    * Update to Beyla 3.9.8.\n * Bug Fixes\n   * security: Update `x/crypto`, `x/net`, `jackc/pgx/v5`, and `obi`.\n   * cluster: Fix nodes failing to join the cluster with TLS enabled.\n   * `loki.process`: Fix potential deadlocks and limit stage shutdown.\n   * Update Go to v1.26.4.\n- Version 1.16.3:\n  * cluster: Fix nodes failing to join the cluster when TLS is enabled.\n- Version 1.16.2:\n  * `loki.process`: No longer mutate rules in `stage.truncate` causing every config update to reload pipeline when this\n    stage is used.\n  * `loki.process`: Potential deadlock on update with stage and receiver changes.\n  * `otelcol.exporter.awss3`: Add missing `unique_key_func_name` attribute.\n- Remove dependency on vulnerable `yaml` library.\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64],{"_key":15},"CVE-2026-25680",{"_key":17},"CVE-2026-25681",{"_key":19},"CVE-2026-27136",{"_key":21},"CVE-2026-33532",{"_key":23},"CVE-2026-39821",{"_key":25},"CVE-2026-39827",{"_key":27},"CVE-2026-39828",{"_key":29},"CVE-2026-39829",{"_key":31},"CVE-2026-39830",{"_key":33},"CVE-2026-39831",{"_key":35},"CVE-2026-39832",{"_key":37},"CVE-2026-39833",{"_key":39},"CVE-2026-39834",{"_key":41},"CVE-2026-39835",{"_key":43},"CVE-2026-41889",{"_key":45},"CVE-2026-42502",{"_key":47},"CVE-2026-42506",{"_key":49},"CVE-2026-42508",{"_key":51},"CVE-2026-44740",{"_key":53},"CVE-2026-45678",{"_key":55},"CVE-2026-45682",{"_key":57},"CVE-2026-45685",{"_key":59},"CVE-2026-45686",{"_key":61},"CVE-2026-46595",{"_key":63},"CVE-2026-46597",{"_key":65},"CVE-2026-46598",[],[],[69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":51},{"_key":53},{"_key":55},{"_key":57},{"_key":59},{"_key":61},{"_key":63},{"_key":65},"2026-07-07T16:59:00Z","2026-07-15T18:24:12.554767538Z",{"cisa_kev":98,"cisa_ransomware":98,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[100,106,111,115,119,123,127,131,135,139,143,147,152,156,160,164,168,172,176,180,184,188,192,196,200,204,208,212,216,220,224,228,232,236,240,244,248],{"url":101,"sources":102,"tags":104},"https://www.suse.com/support/update/announcement/2026/suse-su-202622575-1/",[103],"osv_suse",[105],"Advisory",{"url":107,"sources":108,"tags":109},"https://bugzilla.suse.com/1260981",[103],[110],"REPORT",{"url":112,"sources":113,"tags":114},"https://bugzilla.suse.com/1265440",[103],[110],{"url":116,"sources":117,"tags":118},"https://bugzilla.suse.com/1266196",[103],[110],{"url":120,"sources":121,"tags":122},"https://bugzilla.suse.com/1266654",[103],[110],{"url":124,"sources":125,"tags":126},"https://bugzilla.suse.com/1267185",[103],[110],{"url":128,"sources":129,"tags":130},"https://bugzilla.suse.com/1267333",[103],[110],{"url":132,"sources":133,"tags":134},"https://bugzilla.suse.com/1267481",[103],[110],{"url":136,"sources":137,"tags":138},"https://bugzilla.suse.com/1267485",[103],[110],{"url":140,"sources":141,"tags":142},"https://bugzilla.suse.com/1267488",[103],[110],{"url":144,"sources":145,"tags":146},"https://bugzilla.suse.com/1267489",[103],[110],{"url":148,"sources":149,"tags":150},"https://www.suse.com/security/cve/CVE-2026-25680",[103],[151],"WEB",{"url":153,"sources":154,"tags":155},"https://www.suse.com/security/cve/CVE-2026-25681",[103],[151],{"url":157,"sources":158,"tags":159},"https://www.suse.com/security/cve/CVE-2026-27136",[103],[151],{"url":161,"sources":162,"tags":163},"https://www.suse.com/security/cve/CVE-2026-33532",[103],[151],{"url":165,"sources":166,"tags":167},"https://www.suse.com/security/cve/CVE-2026-39821",[103],[151],{"url":169,"sources":170,"tags":171},"https://www.suse.com/security/cve/CVE-2026-39827",[103],[151],{"url":173,"sources":174,"tags":175},"https://www.suse.com/security/cve/CVE-2026-39828",[103],[151],{"url":177,"sources":178,"tags":179},"https://www.suse.com/security/cve/CVE-2026-39829",[103],[151],{"url":181,"sources":182,"tags":183},"https://www.suse.com/security/cve/CVE-2026-39830",[103],[151],{"url":185,"sources":186,"tags":187},"https://www.suse.com/security/cve/CVE-2026-39831",[103],[151],{"url":189,"sources":190,"tags":191},"https://www.suse.com/security/cve/CVE-2026-39832",[103],[151],{"url":193,"sources":194,"tags":195},"https://www.suse.com/security/cve/CVE-2026-39833",[103],[151],{"url":197,"sources":198,"tags":199},"https://www.suse.com/security/cve/CVE-2026-39834",[103],[151],{"url":201,"sources":202,"tags":203},"https://www.suse.com/security/cve/CVE-2026-39835",[103],[151],{"url":205,"sources":206,"tags":207},"https://www.suse.com/security/cve/CVE-2026-41889",[103],[151],{"url":209,"sources":210,"tags":211},"https://www.suse.com/security/cve/CVE-2026-42502",[103],[151],{"url":213,"sources":214,"tags":215},"https://www.suse.com/security/cve/CVE-2026-42506",[103],[151],{"url":217,"sources":218,"tags":219},"https://www.suse.com/security/cve/CVE-2026-42508",[103],[151],{"url":221,"sources":222,"tags":223},"https://www.suse.com/security/cve/CVE-2026-44740",[103],[151],{"url":225,"sources":226,"tags":227},"https://www.suse.com/security/cve/CVE-2026-45678",[103],[151],{"url":229,"sources":230,"tags":231},"https://www.suse.com/security/cve/CVE-2026-45682",[103],[151],{"url":233,"sources":234,"tags":235},"https://www.suse.com/security/cve/CVE-2026-45685",[103],[151],{"url":237,"sources":238,"tags":239},"https://www.suse.com/security/cve/CVE-2026-45686",[103],[151],{"url":241,"sources":242,"tags":243},"https://www.suse.com/security/cve/CVE-2026-46595",[103],[151],{"url":245,"sources":246,"tags":247},"https://www.suse.com/security/cve/CVE-2026-46597",[103],[151],{"url":249,"sources":250,"tags":251},"https://www.suse.com/security/cve/CVE-2026-46598",[103],[151],[],[],[],[256,269],{"ecosystem":257,"name":258,"vendor":259,"product":260,"cpe_part":9,"purl_type":261,"purl_namespace":259,"purl_name":260,"source":9,"versions":262},"SUSE Linux Enterprise","alloy","suse","alloy&distro=SUSE Linux Enterprise Server 16.0","rpm",[263],{"version":264,"is_range":265,"range_type":266,"version_start":9,"version_start_type":9,"version_end":267,"version_end_type":268,"fixed_in":9},"lt1_17_0_160000_1_1",true,"ecosystem","1.17.0-160000.1.1","excluding",{"ecosystem":257,"name":258,"vendor":259,"product":270,"cpe_part":9,"purl_type":261,"purl_namespace":259,"purl_name":270,"source":9,"versions":271},"alloy&distro=SUSE Linux Enterprise Server for SAP applications 16.0",[272],{"version":264,"is_range":265,"range_type":266,"version_start":9,"version_start_type":9,"version_end":267,"version_end_type":268,"fixed_in":9}]