[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-SUSE-SU-2026:2824-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-01T00:21:03.480Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":68,"duplicates":69,"related":70,"reserved_at":9,"published_at":98,"modified_at":99,"state":9,"summary":100,"references_raw":102,"kevs":263,"epss":9,"epss_history":264,"metrics":265,"affected":266},"SUSE-SU-2026:2824-1","Security update for alloy\n\nThis update for alloy fixes the following issues\n\n- CVE-2026-10722: github.com/cilium/ebpf: BTF string offset boundary check can lead to crash when parsing malformed ELF/BTF input (bsc#1267811).\n- CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html: multiple issues when parsing HTML files (bsc#1267185).\n- CVE-2026-33532: Denial of Service via deeply nested YAML document parsing (bsc#1260981).\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266654).\n- CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833,CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: golang.org/x/crypto/ssh: multiple issues (bsc#1266196).\n- CVE-2026-41889: github.com/jackc/pgx/v5/internal/sanitize: SQL injection when placeholders in dollar-quoted string literals are used in the SQL query (bsc#1265440).\n- CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via infinite loops, panics or resource consumption (bsc#1267333).\n- CVE-2026-45678: go.opentelemetry.io/obi: Postgres BIND parsing can lead to a panic when malformed payloads are processed (bsc#1267481).\n- CVE-2026-45682: go.opentelemetry.io/obi: keys not deleted by `CappedConcurrentHashMap` after removals allows repeated connection churn to grow the queue without bound and exhaust heap memory (bsc#1267485).\n- CVE-2026-45685: go.opentelemetry.io/obi: MongoDB TCP parser panics on malformed wire messages and causes a DoS (bsc#1267488).\n- CVE-2026-45686: go.opentelemetry.io/obi: integer overflow in memcached text protocol parser can crash the OBI process and cause denial of service (bsc#1267489).\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64,66],{"_key":15},"CVE-2026-10722",{"_key":17},"CVE-2026-25680",{"_key":19},"CVE-2026-25681",{"_key":21},"CVE-2026-27136",{"_key":23},"CVE-2026-33532",{"_key":25},"CVE-2026-39821",{"_key":27},"CVE-2026-39827",{"_key":29},"CVE-2026-39828",{"_key":31},"CVE-2026-39829",{"_key":33},"CVE-2026-39830",{"_key":35},"CVE-2026-39831",{"_key":37},"CVE-2026-39832",{"_key":39},"CVE-2026-39833",{"_key":41},"CVE-2026-39834",{"_key":43},"CVE-2026-39835",{"_key":45},"CVE-2026-41889",{"_key":47},"CVE-2026-42502",{"_key":49},"CVE-2026-42506",{"_key":51},"CVE-2026-42508",{"_key":53},"CVE-2026-44740",{"_key":55},"CVE-2026-45678",{"_key":57},"CVE-2026-45682",{"_key":59},"CVE-2026-45685",{"_key":61},"CVE-2026-45686",{"_key":63},"CVE-2026-46595",{"_key":65},"CVE-2026-46597",{"_key":67},"CVE-2026-46598",[],[],[71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":51},{"_key":53},{"_key":55},{"_key":57},{"_key":59},{"_key":61},{"_key":63},{"_key":65},{"_key":67},"2026-07-09T18:18:01Z","2026-07-10T10:00:07.749970540Z",{"cisa_kev":101,"cisa_ransomware":101,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[103,109,114,118,122,126,130,134,138,142,146,150,154,159,163,167,171,175,179,183,187,191,195,199,203,207,211,215,219,223,227,231,235,239,243,247,251,255,259],{"url":104,"sources":105,"tags":107},"https://www.suse.com/support/update/announcement/2026/suse-su-20262824-1/",[106],"osv_suse",[108],"Advisory",{"url":110,"sources":111,"tags":112},"https://bugzilla.suse.com/1260981",[106],[113],"REPORT",{"url":115,"sources":116,"tags":117},"https://bugzilla.suse.com/1265440",[106],[113],{"url":119,"sources":120,"tags":121},"https://bugzilla.suse.com/1266196",[106],[113],{"url":123,"sources":124,"tags":125},"https://bugzilla.suse.com/1266654",[106],[113],{"url":127,"sources":128,"tags":129},"https://bugzilla.suse.com/1267185",[106],[113],{"url":131,"sources":132,"tags":133},"https://bugzilla.suse.com/1267333",[106],[113],{"url":135,"sources":136,"tags":137},"https://bugzilla.suse.com/1267481",[106],[113],{"url":139,"sources":140,"tags":141},"https://bugzilla.suse.com/1267485",[106],[113],{"url":143,"sources":144,"tags":145},"https://bugzilla.suse.com/1267488",[106],[113],{"url":147,"sources":148,"tags":149},"https://bugzilla.suse.com/1267489",[106],[113],{"url":151,"sources":152,"tags":153},"https://bugzilla.suse.com/1267811",[106],[113],{"url":155,"sources":156,"tags":157},"https://www.suse.com/security/cve/CVE-2026-10722",[106],[158],"WEB",{"url":160,"sources":161,"tags":162},"https://www.suse.com/security/cve/CVE-2026-25680",[106],[158],{"url":164,"sources":165,"tags":166},"https://www.suse.com/security/cve/CVE-2026-25681",[106],[158],{"url":168,"sources":169,"tags":170},"https://www.suse.com/security/cve/CVE-2026-27136",[106],[158],{"url":172,"sources":173,"tags":174},"https://www.suse.com/security/cve/CVE-2026-33532",[106],[158],{"url":176,"sources":177,"tags":178},"https://www.suse.com/security/cve/CVE-2026-39821",[106],[158],{"url":180,"sources":181,"tags":182},"https://www.suse.com/security/cve/CVE-2026-39827",[106],[158],{"url":184,"sources":185,"tags":186},"https://www.suse.com/security/cve/CVE-2026-39828",[106],[158],{"url":188,"sources":189,"tags":190},"https://www.suse.com/security/cve/CVE-2026-39829",[106],[158],{"url":192,"sources":193,"tags":194},"https://www.suse.com/security/cve/CVE-2026-39830",[106],[158],{"url":196,"sources":197,"tags":198},"https://www.suse.com/security/cve/CVE-2026-39831",[106],[158],{"url":200,"sources":201,"tags":202},"https://www.suse.com/security/cve/CVE-2026-39832",[106],[158],{"url":204,"sources":205,"tags":206},"https://www.suse.com/security/cve/CVE-2026-39833",[106],[158],{"url":208,"sources":209,"tags":210},"https://www.suse.com/security/cve/CVE-2026-39834",[106],[158],{"url":212,"sources":213,"tags":214},"https://www.suse.com/security/cve/CVE-2026-39835",[106],[158],{"url":216,"sources":217,"tags":218},"https://www.suse.com/security/cve/CVE-2026-41889",[106],[158],{"url":220,"sources":221,"tags":222},"https://www.suse.com/security/cve/CVE-2026-42502",[106],[158],{"url":224,"sources":225,"tags":226},"https://www.suse.com/security/cve/CVE-2026-42506",[106],[158],{"url":228,"sources":229,"tags":230},"https://www.suse.com/security/cve/CVE-2026-42508",[106],[158],{"url":232,"sources":233,"tags":234},"https://www.suse.com/security/cve/CVE-2026-44740",[106],[158],{"url":236,"sources":237,"tags":238},"https://www.suse.com/security/cve/CVE-2026-45678",[106],[158],{"url":240,"sources":241,"tags":242},"https://www.suse.com/security/cve/CVE-2026-45682",[106],[158],{"url":244,"sources":245,"tags":246},"https://www.suse.com/security/cve/CVE-2026-45685",[106],[158],{"url":248,"sources":249,"tags":250},"https://www.suse.com/security/cve/CVE-2026-45686",[106],[158],{"url":252,"sources":253,"tags":254},"https://www.suse.com/security/cve/CVE-2026-46595",[106],[158],{"url":256,"sources":257,"tags":258},"https://www.suse.com/security/cve/CVE-2026-46597",[106],[158],{"url":260,"sources":261,"tags":262},"https://www.suse.com/security/cve/CVE-2026-46598",[106],[158],[],[],[],[267],{"ecosystem":268,"name":269,"vendor":270,"product":271,"cpe_part":9,"purl_type":272,"purl_namespace":270,"purl_name":271,"source":9,"versions":273},"SUSE Linux Enterprise","alloy","suse","alloy&distro=SUSE Linux Enterprise Module for Basesystem 15 SP7","rpm",[274],{"version":275,"is_range":276,"range_type":277,"version_start":9,"version_start_type":9,"version_end":278,"version_end_type":279,"fixed_in":9},"lt1_17_1_150700_15_23_1",true,"ecosystem","1.17.1-150700.15.23.1","excluding"]