[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-SUSE-SU-2026:2493-1":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T11:35:27.363Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":38,"duplicates":39,"related":40,"reserved_at":9,"published_at":53,"modified_at":54,"state":9,"summary":55,"references_raw":57,"kevs":142,"epss":9,"epss_history":143,"metrics":144,"affected":145},"SUSE-SU-2026:2493-1","Security update for containerized-data-importer\n\nThis update for containerized-data-importer fixes the following issues:\n\n- Security: re-vendor Go dependencies to address CVEs tracked against\n  containerized-data-importer (backport of upstream PR #4110, post-v1.65.0).\n  Fixed by this update:\n  * google.golang.org/grpc 1.65.0 -> 1.79.3:\n    bsc#1260295 (CVE-2026-33186)\n  * golang.org/x/net 0.33.0 -> 0.48.0:\n    bsc#1238699 (CVE-2025-22870), bsc#1241838 (CVE-2025-22872),\n    bsc#1251495 (CVE-2025-47911), bsc#1251689 (CVE-2025-58190)\n  * golang.org/x/crypto 0.31.0 -> 0.46.0:\n    CVE-2025-22869, CVE-2025-47913, CVE-2025-47914, CVE-2025-58181\n    (no separate CDI bug filed)\n  * go.opentelemetry.io/otel 1.28.0 -> 1.41.0:\n    CVE-2026-29181 (otel is pulled in transitively at 1.39.0 by the grpc\n    bump; pinned to 1.41.0 so the update does not introduce it)\n- Record CVEs already fixed by the x/net release vendored in 1.64.0\n  (x/net 0.33.0), not previously noted in the changelog:\n  bsc#1236523 (CVE-2023-45288), bsc#1230323 (CVE-2023-39325)\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36],{"_key":15},"CVE-2023-39325",{"_key":17},"CVE-2023-45288",{"_key":19},"CVE-2025-22869",{"_key":21},"CVE-2025-22870",{"_key":23},"CVE-2025-22872",{"_key":25},"CVE-2025-47911",{"_key":27},"CVE-2025-47913",{"_key":29},"CVE-2025-47914",{"_key":31},"CVE-2025-58181",{"_key":33},"CVE-2025-58190",{"_key":35},"CVE-2026-29181",{"_key":37},"CVE-2026-33186",[],[],[41,42,43,44,45,46,47,48,49,50,51,52],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},"2026-06-22T15:34:20Z","2026-06-24T09:00:13.323582618Z",{"cisa_kev":56,"cisa_ransomware":56,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[58,64,69,73,77,81,85,89,93,98,102,106,110,114,118,122,126,130,134,138],{"url":59,"sources":60,"tags":62},"https://www.suse.com/support/update/announcement/2026/suse-su-20262493-1/",[61],"osv_suse",[63],"Advisory",{"url":65,"sources":66,"tags":67},"https://bugzilla.suse.com/1230323",[61],[68],"REPORT",{"url":70,"sources":71,"tags":72},"https://bugzilla.suse.com/1236523",[61],[68],{"url":74,"sources":75,"tags":76},"https://bugzilla.suse.com/1238699",[61],[68],{"url":78,"sources":79,"tags":80},"https://bugzilla.suse.com/1241838",[61],[68],{"url":82,"sources":83,"tags":84},"https://bugzilla.suse.com/1251495",[61],[68],{"url":86,"sources":87,"tags":88},"https://bugzilla.suse.com/1251689",[61],[68],{"url":90,"sources":91,"tags":92},"https://bugzilla.suse.com/1260295",[61],[68],{"url":94,"sources":95,"tags":96},"https://www.suse.com/security/cve/CVE-2023-39325",[61],[97],"WEB",{"url":99,"sources":100,"tags":101},"https://www.suse.com/security/cve/CVE-2023-45288",[61],[97],{"url":103,"sources":104,"tags":105},"https://www.suse.com/security/cve/CVE-2025-22869",[61],[97],{"url":107,"sources":108,"tags":109},"https://www.suse.com/security/cve/CVE-2025-22870",[61],[97],{"url":111,"sources":112,"tags":113},"https://www.suse.com/security/cve/CVE-2025-22872",[61],[97],{"url":115,"sources":116,"tags":117},"https://www.suse.com/security/cve/CVE-2025-47911",[61],[97],{"url":119,"sources":120,"tags":121},"https://www.suse.com/security/cve/CVE-2025-47913",[61],[97],{"url":123,"sources":124,"tags":125},"https://www.suse.com/security/cve/CVE-2025-47914",[61],[97],{"url":127,"sources":128,"tags":129},"https://www.suse.com/security/cve/CVE-2025-58181",[61],[97],{"url":131,"sources":132,"tags":133},"https://www.suse.com/security/cve/CVE-2025-58190",[61],[97],{"url":135,"sources":136,"tags":137},"https://www.suse.com/security/cve/CVE-2026-29181",[61],[97],{"url":139,"sources":140,"tags":141},"https://www.suse.com/security/cve/CVE-2026-33186",[61],[97],[],[],[],[146],{"ecosystem":147,"name":148,"vendor":149,"product":150,"cpe_part":9,"purl_type":151,"purl_namespace":149,"purl_name":150,"source":9,"versions":152},"SUSE Linux Enterprise","containerized-data-importer","suse","containerized-data-importer&distro=SUSE Linux Enterprise Module for Containers 15 SP7","rpm",[153],{"version":154,"is_range":155,"range_type":156,"version_start":9,"version_start_type":9,"version_end":157,"version_end_type":158,"fixed_in":9},"lt1_64_0_150700_9_11_1",true,"ecosystem","1.64.0-150700.9.11.1","excluding"]