[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-SUSE-SU-2026:2438-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-01T00:21:03.480Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":26,"duplicates":27,"related":28,"reserved_at":9,"published_at":35,"modified_at":36,"state":9,"summary":37,"references_raw":39,"kevs":96,"epss":9,"epss_history":97,"metrics":98,"affected":99},"SUSE-SU-2026:2438-1","Security update for alloy\n\nThis update for alloy fixes the following issues\n\nSecurity issues:\n\n- CVE-2026-4427: github.com/jackc/pgproto3/v2: improper validation of field length allows a malicious PostgreSQL server\n  to crash a client application via a DataRow message (bsc#1259919).\n- CVE-2026-25934: github.com/go-git/go-git/v5: improper verification of data integrity values for .pack and .idx files\n  can lead to the consumption of corrupted files (bsc#1258099).\n- CVE-2026-26958: filippo.io/edwards25519: failure to initialize receiver in MultiScalarMult can produce invalid results\n  and lead to undefined behavior (bsc#1258609).\n- CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo-\n  header (bsc#1260317).\n- CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of\n  service (bsc#1262955).\n- CVE-2026-41602: github.com/apache/thrift: TFramedTransport frame size headers can lead to a uint32 integer overflow\n  (bsc#1263530).\n\nNon security issue:\n\n- Use systemd tmpfiles.d to create /var/lib/alloy hierarchy (jsc#PED-14815).\n- Update to version 1.16.1\n * Bug Fixes\n logging: Fix startup deadlock when components log before\n logging config is evaluated\n Update to Beyla 3.9.8\n Migrate from Docker to Moby\n- Use latest openSUSE Tumbleweed image for building web UI assets\n- Install nvm to set node version specified upstream\n- update to 1.16.0:\n * Features\n - Add clustering for loki.source.kubernetes_events (#6027)\n (3dbf587) (@petewall)\n - Add otelcol.auth.google client auth provider (#5526)\n (da99a66) (@dashpole, @clayton-cornell)\n - beyla.ebpf: Bump to v3.7.0 (#5966) (5126c2e) (@marctc)\n - database_observability: Add support for GCP Cloud SQL\n metadata (#5875) (5d23245) (@cristiangreco, @clayton-cornell)\n - database_observability: Make targets optional (#5924)\n (54664b2) (@matthewnolf)\n - database_observability: Update default excluded schemas and\n users (#6080) (b386fff) (@cristiangreco)\n - faro.receiver: Add sourcemap fetching from remote locations\n (#4614) (b6cb5da) (@Oxel40)\n - helm: Add support for global.image.pullPolicy (#6069)\n (2e2ce72) (@petewall)\n - helm: Allow configuring image pull policy for config reloader\n (#5923) (991539b) (@kalleep)\n - loki.secretfilter: Add label_timed_out option to mark\n timed-out log lines (#5898) (2ad8834) (@kleimkuhler)\n - loki.secretfilter: Add secrets_redacted_by_category_total\n metric combining rule and origin (#5855) (053a2f7)\n (@kleimkuhler)\n - loki.secretfilter: Change secretfilter to use go-re2 regex\n library instead of stdlib (#5909) (c16a660) (@mikefat)\n - loki.secretfilter: Remove redundant\n secrets_redacted_by_rule_total and secrets_redacted_by_origin\n metrics (#5970) (b16decb) (@kleimkuhler)\n - Oracle exporter can scrape more than one DB (#6008) (6fbad38)\n (@ptodev)\n - prometheus.exporter.cloudwatch: Upgrade YACE and drop\n aws-sdk-go v1 support (#5936) (f1c036d) (@x1unix)\n - prometheus.exporter.mysql: Update to mysqld_exporter 0.19.0\n (#5836) (4f49b57) (@cristiangreco)\n - prometheus.remote_write: Sync WAL with upstream Prometheus\n (#5907) (e74a91b) (@x1unix)\n - pyroscope: Add support for extra async-profiler CLI arguments\n (#5472) (9251e33) (@ivanape)\n - pyroscope: Replace Parca gRPC debuginfo upload with Pyroscope\n Connect API (#5891) (e7ea34a) (@korniltsev-grafanista)\n - pyroscope: Update debuginfo client for HTTP/1.1 upload API\n (#6037) (879d8e5) (@korniltsev-grafanista)\n - Change service stop command from 'sc' to 'net' (#5906)\n (450973d) (@mateuszdrab)\n - database_observability.mysql: Refactor explain plan loop\n batch size (#5894) (f0fcd6b) (@cristiangreco)\n - database_observability.postgres: Cleanup embedded exporter\n collectors on reconnection (#6079) (f30d9ae) (@cristiangreco)\n - database_observability.postgres: Fix EXPLAIN param count when\n placeholders repeat (#6082) (b612b81) (@rgeyer)\n - database_observability: Drop schema_detection from logs\n (#6076) (b0105cb) (@cristiangreco)\n - database_observability: Ensure connection_info_monitor\n goroutine exits on Stop (#5874) (1e3334b) (@cristiangreco)\n - deps: Update module github.com/aws/aws-sdk-go-v2/service/s3\n to v1.97.3 [SECURITY] (#6004) (38f4346)\n - deps: Update module github.com/go-git/go-git/v5 to v5.17.1\n [SECURITY] (#5934) (a5154af)\n - deps: Update module github.com/go-git/go-git/v5 to v5.18.0\n [SECURITY] (#6090) (0e59d64)\n - deps: Update module github.com/nwaples/rardecode/v2 to v2.2.0\n [SECURITY] (b44d51a) (@jharvey10)\n - deps: Update module\n go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp\n to v1.43.0 [SECURITY] (#6016) (d92c5c0)\n go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp\n to v1.43.0 [SECURITY] (#6017) (e655bbc)\n - deps: Update module go.opentelemetry.io/otel/sdk to v1.43.0\n [SECURITY] (#6018) (94006e8)\n - deps: Update some minor go dep versions (#5896) (4ddd0ed)\n (@jharvey10)\n - go: Update alloy builder image to Go 1.25.9 (#6012) (d2ae8b8)\n (@x1unix)\n - go: Upgrade to Go 1.25.9 (#6019) (d777ed1) (@x1unix,\n @kalleep)\n - Helm: RBAC template handles empty rule arrays (#4860)\n (c9430e9) (@naptalie, @dehaansa, @kalleep)\n - loki.process: Eliminate per-stream goroutines in multiline\n stage (#6036) (c089e2e) (@kgeckhart)\n - loki.process: Prevent stage.structured_metadata from adding\n the same metadata several times (#5965) (0ec8a26) (@kalleep,\n @thampiotr)\n - loki.process: Wrap template in a custom type and move\n validation to syntax.Validator (#5910) (700dd7d) (@kalleep)\n - prometheus.exporter.postgres: Close DB connections on update\n (#6021) (8da97cf) (@kalleep)\n - prometheus.scrape: Update scrape_native_histograms to be\n updated at runtime (#6087) (18b205c) (@kalleep)\n - pyroscope.ebpf: Fix deadlock on LRU eviction in irsymcache\n (#5911) (03ca563) (@luweglarz)\n - pyroscope.ebpf: Move Pyroscope ebpf metrics registration\n after component error handling (#5540) (a3c57c0) (@crbednarz,\n @marcsanmi)\n - pyroscope: Set user agent on debuginfo connect-go client\n (#6022) (38ad1ef) (@korniltsev-grafanista)\n - ui: Large arguments are downloaded as files instead of\n rendered (#5268) (26c67b3) (@ptodev)\n - Update go-m1cpu v0.1.7 -> v0.2.1 to fix M5 chip crash (#6034)\n (7fa0cbc) (@ymotongpoo)\n - windows-installer: Increase service restart on failure delays\n (#5969) (add15b1) (@rknightion)\n- add script to package webassets inside a podman container, to not\n endanger or pollute the host system with npm\n- update to 1.15.1:\n goroutine exits on Stop\n * CVE-2026-34986: Fix panic in JWE decryption (bsc#1262955)\n- update to 1.15.0:\n * BREAKING CHANGES\n - otelcol: Upgrade to OTel Collector v0.147.0\n - Renamed undocumented metrics that was previously prefixed\n with \u003Ccomponent_id>\u003Cmetric_name> to\n loki_source_awsfirehose\u003Cmetric_name>\n * Security\n CVE-2026-26958: Update filippo.io/edwards25519 to version 1.1.1\n (bsc#1258609).\n - alloy-mixin: Add filters, groupBy, and multi-select dashboard\n variables\n - beyla.ebpf: Add support for Prometheus native histograms\n - beyla.ebpf: Bump Beyla to v3.6\n - converters: Support converting Promtail limits_config\n - database_observability.mysql: Add filtering of query samples\n and wait events by minimum duration\n - database_observability.mysql: Embed prometheus exporter\n within db-o11y component\n - database_observability.postgres: Add configurable limit to\n pg_stat_statements query\n - database_observability.postgres: Embed prometheus exporter\n - database_observability: Promote components to stable\n - Expose Functionality to Handle syslogs with Empty MSG Field\n - loki.process: Support structured metadata as source type of\n stage.labels for loki.process\n - loki.secretfilter: Add sampling for secretfilter entries\n - loki.source.gcplog: Add alloy config for MaxOutstandingBytes\n and MaxOutstandingMessages\n - loki.write: Add loki pipeline latency metric\n - mixin: Update loki dashboard\n - otelcol.receiver.datadog: Expose intake proxy and\n trace_id_cache_size settings\n - prometheus.exporter.cloudwatch: Use aws-sdk-go-v2 by default\n - pyroscope.ebpf: Add comm, pid labels and kernel frame options\n- update to 1.14.1:\n - Correctly handle the deprecated topic field in\n otelcol.receiver.kafka configuration\n - loki.process: Protect against json that does not look like\n docker json format\n - loki.source.file: Keep positions for compressed files when\n reading is finished\n - prometheus.scrape: Update arguments and targets even if\n scrape_native_histograms and extra_metrics are updated\n- update to 1.14.0:\n - loki.secretfilter: Some config options are removed entirely:\n partial_mask (replaced with redact_percent), allowlist (now\n controlled with custom gitleaks config), enable_entropy,\n include_generic, types (now controlled with custom gitleaks\n config).\n - otelcol.receiver.prometheus: otelcol.receiver.prometheus no\n longer sets start times of OTLP metrics.\n * Security:\n- update to 1.13.2:\n - Expose missing otelcol.processor.tail_sampling options\n - mixin: Add zipped dashboards as a release artifact\n - profiler: Backport Go 1.26 gopclntab textStart fix\n - prometheus.exporter.postgres: Update version of the exporter\n fork to fix pg_settings\n - pyroscope.ebpf: Backport dotnet nibble map fix\n- update to 1.13.1:\n - timeout before starting new ones\n- update to 1.13.0:\n - otelcol: Upgrade to OTel Collector v0.142.0\n - otelcol.receiver.kafka: The global topic attribute has been\n deleted; use the topics attributes inside the logs, metrics,\n and traces blocks instead.\n - otelcol.exporter > sending_queue > batch > min_size changed\n from 8192 to 2000 and max_size changed from 0 to 3000\n - Add a virtual_node_peer_attributes and\n virtual_node_extra_label arguments to\n otelcol.connector.servicegraph\n - Add an otelcol.processor.metric_start_time component\n - Add job level period, length, and add_cloudwatch_timestamp\n options and labels_snake_case to CW exporter\n - Add missing configuration parameter\n deployment_name_from_replicaset to k8sattributes processor\n - Add parcas symbols upload to pyroscope.ebpf\n - Add sharding for loki.write\n - Add unexposed otel engine and extension to codebase and\n change build structure\n - beyla.ebpf: Add meta_cache_address to\n beyla.ebpf.attributes.kubernetes\n - beyla.ebpf: Upgrade Beyla to v2.8.5\n - Change the defaults for sending_queue > batch block inside\n otelcol.exporter components\n - cluster: Support DNS discovery mode prefixes in\n --cluster.join-addresses flag\n - converter: Update promtail converter to use file_match block\n for loki.source.file\n - database_observability: Add health check collector for\n postgres component\n - database_observability: Expose exclude_schemas and\n exclude_databases settings\n - database_observability: Support Azure cloud provider config\n data\n - database_observability.mysql: Support excluding schemas in\n all collectors\n - database_observability.postgres: Support excluding DBs in all\n collectors\n",null,[],[],[],[14,16,18,20,22,24],{"_key":15},"CVE-2026-25934",{"_key":17},"CVE-2026-26958",{"_key":19},"CVE-2026-33186",{"_key":21},"CVE-2026-34986",{"_key":23},"CVE-2026-41602",{"_key":25},"CVE-2026-4427",[],[],[29,30,31,32,33,34],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},"2026-06-17T14:45:01Z","2026-06-18T08:15:04.326830274Z",{"cisa_kev":38,"cisa_ransomware":38,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[40,46,51,55,59,63,67,71,76,80,84,88,92],{"url":41,"sources":42,"tags":44},"https://www.suse.com/support/update/announcement/2026/suse-su-20262438-1/",[43],"osv_suse",[45],"Advisory",{"url":47,"sources":48,"tags":49},"https://bugzilla.suse.com/1258099",[43],[50],"REPORT",{"url":52,"sources":53,"tags":54},"https://bugzilla.suse.com/1258609",[43],[50],{"url":56,"sources":57,"tags":58},"https://bugzilla.suse.com/1259919",[43],[50],{"url":60,"sources":61,"tags":62},"https://bugzilla.suse.com/1260317",[43],[50],{"url":64,"sources":65,"tags":66},"https://bugzilla.suse.com/1262955",[43],[50],{"url":68,"sources":69,"tags":70},"https://bugzilla.suse.com/1263530",[43],[50],{"url":72,"sources":73,"tags":74},"https://www.suse.com/security/cve/CVE-2026-25934",[43],[75],"WEB",{"url":77,"sources":78,"tags":79},"https://www.suse.com/security/cve/CVE-2026-26958",[43],[75],{"url":81,"sources":82,"tags":83},"https://www.suse.com/security/cve/CVE-2026-33186",[43],[75],{"url":85,"sources":86,"tags":87},"https://www.suse.com/security/cve/CVE-2026-34986",[43],[75],{"url":89,"sources":90,"tags":91},"https://www.suse.com/security/cve/CVE-2026-41602",[43],[75],{"url":93,"sources":94,"tags":95},"https://www.suse.com/security/cve/CVE-2026-4427",[43],[75],[],[],[],[100],{"ecosystem":101,"name":102,"vendor":103,"product":104,"cpe_part":9,"purl_type":105,"purl_namespace":103,"purl_name":104,"source":9,"versions":106},"SUSE Linux Enterprise","alloy","suse","alloy&distro=SUSE Linux Enterprise Module for Basesystem 15 SP7","rpm",[107],{"version":108,"is_range":109,"range_type":110,"version_start":9,"version_start_type":9,"version_end":111,"version_end_type":112,"fixed_in":9},"lt1_16_1_150700_15_20_1",true,"ecosystem","1.16.1-150700.15.20.1","excluding"]