[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-SUSE-SU-2026:4212-1":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T11:35:27.363Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":56,"duplicates":57,"related":58,"reserved_at":9,"published_at":80,"modified_at":81,"state":9,"summary":82,"references_raw":84,"kevs":217,"epss":9,"epss_history":218,"metrics":219,"affected":220},"SUSE-SU-2026:4212-1","Security update for distribution\n\nThis update for distribution fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo-\n  header (bsc#1260283).\n- CVE-2026-33540: information disclosure via improper validation of authentication realm URL (bsc#1261793).\n- CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE\n  (bsc#1265788).\n- CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of\n  service (bsc#1262951).\n- CVE-2026-35172: information disclosure via stale references after content deletion (bsc#1262096).\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation\n  bypass and privilege escalation (bsc#1266629).\n- CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,\n  CVE-2026-39832,CVE-2026-39833,CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,\n  CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: golang.org/x/crypto/ssh: multiple issues (bsc#1268884).\n- CVE-2026-41888: tag deletion bypasses the storage.delete.enabled configuration (bsc#1265429).\n- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272132).\n\nChanges for distribution:\n\nUpdate to 3.1.1:\n\n * Bounds-check the file basename in PurgeUploads Walk callback\n * Add S3 Express One Zone support to the S3 storage driver\n * Fix tag list endpoint in proxy mode\n * Clamp oversized `n` query parameter in proxy mode instead of\n returning 400\n * See the full changelog below for the full list of changes.\n * internal/client/auth/challenge: cleanups and minor refactor\n * build(deps): bump\n go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp\n from 0.18.0 to 0.19.0 in the go_modules group across 1\n directory\n * build(deps): bump go.opentelemetry.io/otel/exporters/otlp/otl\n ptrace/otlptracehttp from 1.42.0 to 1.43.0 in the go_modules\n group across 1 directory\n * build(deps): bump github/codeql-action from 4.34.1 to 4.35.1\n * chore(build): Bump go version to latest\n * refactor: use slices.Backward to simplify the code\n * fix(proxy): fix tag list endpoint in proxy mode\n * Update docker-compose structure in deploying.md\n * build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1\n * build(deps): bump actions/upload-pages-artifact from 4.0.0 to\n 5.0.0\n * build(deps): bump docker/login-action from 4.0.0 to 4.1.0\n * build(deps): bump docker/bake-action from 7.0.0 to 7.1.0\n * fix(proxy): clamp oversized n query param instead of\n * feat(s3): add express zone one support to S3 driver\n * fix(storage): bounds-check the file basename in PurgeUploads\n Walk callback\n * chore(release): prepare for v3.1.1 release\n * Adds support for tag pagination\n * Fixes default credentials in Azure storage provider\n * Drops support for go1.23 and go1.24 and updates to go1.25\n * docs: Update to refer to new image tag v3\n * Fix default_credentials in azure storage provider\n * chore: make function comment match function name\n * build(deps): bump golang.org/x/net from 0.37.0 to 0.38.0 in\n the go_modules group across 1 directory\n * fix: implement JWK thumbprint for Ed25519 public keys\n * fix: Annotate code block from validation.indexes\n configuration docs\n * feat: extract redis config to separate struct\n * Fix: resolve issue #4478 by using a temporary file for non-\n append writes\n * build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2\n * docs: Add note about `OTEL_TRACES_EXPORTER`\n * fix: set OTEL traces to disabled by default\n * Fix markdown syntax for OTEL traces link in docs\n * Switch UUIDs to UUIDv7\n * refactor: replace map iteration with maps.Copy/Clone\n * s3-aws: fix build for 386\n * docs: Add OpenTelemetry links to quickstart docs\n * Fix S3 driver loglevel param\n * Fixed data race in TestSchedule test\n * Fixes #4683 - uses X/Y instead of Gx/Gy for thumbprint of\n ecdsa keys\n * build(deps): bump actions/checkout from 4 to 5\n * Fix broken link to Docker Hub fair use policy\n * fix(registry/handlers/app): redis CAs\n * build(deps): bump actions/labeler from 5 to 6\n * build(deps): bump actions/setup-go from 5 to 6\n * build(deps): bump actions/upload-pages-artifact from 3 to 4\n * build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3\n * build(deps): bump github/codeql-action from 3.26.5 to 4.30.7\n * build(deps): bump github/codeql-action from 4.30.7 to 4.30.8\n * chore: labeler: add area/client mapping for\n internal/client/**\n * client: add Accept headers to Exists() HEAD\n * feat(registry): Make graceful shutdown test robust\n * fix(registry): Correct log formatting for upstream challenge\n * build(deps): bump github/codeql-action from 4.30.8 to 4.30.9\n * build(deps): bump github/codeql-action from 4.30.9 to 4.31.3\n * refactor: remove redundant variable declarations in for loops\n * 'should' -> 'must' regarding redis eviction policy\n * build(deps): bump actions/checkout from 5 to 6\n * Incorrect warning hint\n * Add return error when list object\n * build(deps): bump actions/checkout from 5.0.1 to 6.0.0\n * build(deps): bump peter-evans/dockerhub-description from 4 to\n 5\n * fix: Logging regression for manifest HEAD requests\n * Add boolean parsing util\n * Expose `useFIPSEndpoint` for S3\n * Add Cloudfleet Container Registry to adopters\n * fix(ci): Fix broken Azure e2e storage tests\n * BUG: Fix notification filtering to work with actions when\n mediatypes is empty\n * build(deps): bump actions/checkout from 6.0.0 to 6.0.1\n * build(deps): bump actions/upload-artifact from 4.6.2 to 6.0.0\n * build(deps): bump github/codeql-action from 4.31.3 to 4.31.10\n * build(deps): bump github/codeql-action from 4.31.10 to 4.32.2\n * build(deps): bump actions/checkout from 6.0.1 to 6.0.2\n * update golangci-lint to v2.9 and fix linting issues\n * update to go1.25.7, alpine 3.23, xx v1.9.0\n * vendor: github.com/sirupsen/logrus v1.9.4\n * vendor: update golang.org/x/* dependencies\n * vendor: github.com/docker/docker-credential-helpers v0.9.5\n * vendor: github.com/opencontainers/image-spec v1.1.1\n * vendor: github.com/klauspost/compress v1.18.4\n * fix: prefer otel variables over hard coded service name\n * vendor: github.com/spf13/cobra v1.10.2\n * vendor: github.com/bshuster-repo/logrus-logstash-hook v1.1.0\n * fix: sync parent dir to ensure data is reliably stored\n * modernize code\n * vendor: github.com/docker/go-events 605354379745\n * vendor: github.com/go-jose/go-jose/v4 v4.1.3\n * build(deps): bump github/codeql-action from 4.32.2 to 4.32.5\n * build(deps): bump docker/login-action from 3 to 4\n * build(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0\n * build(deps): bump docker/setup-buildx-action from 3 to 4\n * build(deps): bump docker/bake-action from 6 to 7\n * build(deps): bump docker/metadata-action from 5 to 6\n * fix: nil-check scheduler in `proxyingRegistry.Close()`\n * fix: set MD5 on GCS writer before first `Write` call in\n `putContent`\n * docs: pull through cache will pull from remote multiple times\n * Update s3.md regionendpoint option\n * chore(deps): Bump Go to latest 1.25 in CI workflows and\n go.mod\n * fix: correct Ed25519 JWK thumbprint `kty` from `'OTP'` to\n `'OKP'`\n * Update vacuum.go\n * Opt: refector tag list pagination support (stage 1)\n * Correctly match environment variables to YAML-inlined structs\n in configuration\n * Enable Redis TLS without client certificates\n * build(deps): bump actions/deploy-pages from 4 to 5\n * build(deps): bump github/codeql-action from 4.32.5 to 4.34.1\n * fix(registry/proxy): use detached context when flushing write\n buffer\n * ci: pin actions and apply zizmor auto-fixes\n * build(deps): bump actions/setup-go from 6.3.0 to 6.4.0\n * build(deps): bump github.com/go-jose/go-jose/v4 from 4.1.3 to\n 4.1.4 in the go_modules group across 1 directory\n * chore(app): warn when partial TLS config is used in Redis\n * feat(registry): enhance authentication checks in htpasswd\n implementation\n * Opt: refactor tag list pagination support\n * build(deps): bump codecov/codecov-action from 5.5.4 to 6.0.0\n * build(deps): bump actions/configure-pages from 5.0.0 to 6.0.0\n * fix(vendor): fix broke vendor validation\n * chore(ci): Prep for v3.1 release\n- Update to version 3.1.0:\n * fix(vendor): fix broke vendpor validation\n * fix redis repo-scoped blob descriptor revocation\n * proxy: bind bearer realms to upstream trust boundary\n- restore directory ownership after last change\n- Move config files in systemd tmpfiles dir for immutable mode\n (jsc#PED-14747)\n * Add distribution-registry.tmpfiles\n * This is the first v3 stable release since `v2.8.3` which is a\n culmination of years of hard work of the container community\n and registry maintainers!\n * If you are upgrading from `v2.x` and have never used any of\n the release candidates, please familiarise yourselves with\n the `v2.x` deprecations properly.\n * oss and swift storage drivers are no longer supported\n * `docker/libtrust` has been replaced with `go-jose/go-jose` in\n https://github.com/distribution/distribution/pull/4096\n * `client` is no longer supported as a standalone package in\n https://github.com/distribution/distribution/pull/4126\n * the default configuration path has changed to\n `/etc/distribution/config.yml`\n * `ManifestBuilder` interface in 3886\n * `manifest.Versioned` has been deprecated in favor of\n `oci.Versioned` in 3887\n * `reference` package has been moved to\n github.com/distribution/reference in\n https://github.com/distribution/distribution/pull/4063\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54],{"_key":15},"CVE-2026-33186",{"_key":17},"CVE-2026-33540",{"_key":19},"CVE-2026-33814",{"_key":21},"CVE-2026-34986",{"_key":23},"CVE-2026-35172",{"_key":25},"CVE-2026-39821",{"_key":27},"CVE-2026-39827",{"_key":29},"CVE-2026-39828",{"_key":31},"CVE-2026-39829",{"_key":33},"CVE-2026-39830",{"_key":35},"CVE-2026-39831",{"_key":37},"CVE-2026-39832",{"_key":39},"CVE-2026-39833",{"_key":41},"CVE-2026-39834",{"_key":43},"CVE-2026-39835",{"_key":45},"CVE-2026-41888",{"_key":47},"CVE-2026-42508",{"_key":49},"CVE-2026-46595",{"_key":51},"CVE-2026-46597",{"_key":53},"CVE-2026-46598",{"_key":55},"CVE-2026-56852",[],[],[59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":51},{"_key":53},{"_key":55},"2026-09-16T11:52:48Z","2026-09-16T21:45:07.142110952Z",{"cisa_kev":83,"cisa_ransomware":83,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[85,91,96,100,104,108,112,116,120,124,128,132,137,141,145,149,153,157,161,165,169,173,177,181,185,189,193,197,201,205,209,213],{"url":86,"sources":87,"tags":89},"https://www.suse.com/support/update/announcement/2026/suse-su-20264212-1/",[88],"osv_suse",[90],"Advisory",{"url":92,"sources":93,"tags":94},"https://bugzilla.suse.com/1259718",[88],[95],"REPORT",{"url":97,"sources":98,"tags":99},"https://bugzilla.suse.com/1260283",[88],[95],{"url":101,"sources":102,"tags":103},"https://bugzilla.suse.com/1261793",[88],[95],{"url":105,"sources":106,"tags":107},"https://bugzilla.suse.com/1262096",[88],[95],{"url":109,"sources":110,"tags":111},"https://bugzilla.suse.com/1262951",[88],[95],{"url":113,"sources":114,"tags":115},"https://bugzilla.suse.com/1265429",[88],[95],{"url":117,"sources":118,"tags":119},"https://bugzilla.suse.com/1265788",[88],[95],{"url":121,"sources":122,"tags":123},"https://bugzilla.suse.com/1266629",[88],[95],{"url":125,"sources":126,"tags":127},"https://bugzilla.suse.com/1268884",[88],[95],{"url":129,"sources":130,"tags":131},"https://bugzilla.suse.com/1272132",[88],[95],{"url":133,"sources":134,"tags":135},"https://www.suse.com/security/cve/CVE-2026-33186",[88],[136],"WEB",{"url":138,"sources":139,"tags":140},"https://www.suse.com/security/cve/CVE-2026-33540",[88],[136],{"url":142,"sources":143,"tags":144},"https://www.suse.com/security/cve/CVE-2026-33814",[88],[136],{"url":146,"sources":147,"tags":148},"https://www.suse.com/security/cve/CVE-2026-34986",[88],[136],{"url":150,"sources":151,"tags":152},"https://www.suse.com/security/cve/CVE-2026-35172",[88],[136],{"url":154,"sources":155,"tags":156},"https://www.suse.com/security/cve/CVE-2026-39821",[88],[136],{"url":158,"sources":159,"tags":160},"https://www.suse.com/security/cve/CVE-2026-39827",[88],[136],{"url":162,"sources":163,"tags":164},"https://www.suse.com/security/cve/CVE-2026-39828",[88],[136],{"url":166,"sources":167,"tags":168},"https://www.suse.com/security/cve/CVE-2026-39829",[88],[136],{"url":170,"sources":171,"tags":172},"https://www.suse.com/security/cve/CVE-2026-39830",[88],[136],{"url":174,"sources":175,"tags":176},"https://www.suse.com/security/cve/CVE-2026-39831",[88],[136],{"url":178,"sources":179,"tags":180},"https://www.suse.com/security/cve/CVE-2026-39832",[88],[136],{"url":182,"sources":183,"tags":184},"https://www.suse.com/security/cve/CVE-2026-39833",[88],[136],{"url":186,"sources":187,"tags":188},"https://www.suse.com/security/cve/CVE-2026-39834",[88],[136],{"url":190,"sources":191,"tags":192},"https://www.suse.com/security/cve/CVE-2026-39835",[88],[136],{"url":194,"sources":195,"tags":196},"https://www.suse.com/security/cve/CVE-2026-41888",[88],[136],{"url":198,"sources":199,"tags":200},"https://www.suse.com/security/cve/CVE-2026-42508",[88],[136],{"url":202,"sources":203,"tags":204},"https://www.suse.com/security/cve/CVE-2026-46595",[88],[136],{"url":206,"sources":207,"tags":208},"https://www.suse.com/security/cve/CVE-2026-46597",[88],[136],{"url":210,"sources":211,"tags":212},"https://www.suse.com/security/cve/CVE-2026-46598",[88],[136],{"url":214,"sources":215,"tags":216},"https://www.suse.com/security/cve/CVE-2026-56852",[88],[136],[],[],[],[221,234,238,242,246,250,254,258,262,266,270],{"ecosystem":222,"name":223,"vendor":224,"product":225,"cpe_part":9,"purl_type":226,"purl_namespace":224,"purl_name":225,"source":9,"versions":227},"SUSE Linux Enterprise","distribution","suse","distribution&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS","rpm",[228],{"version":229,"is_range":230,"range_type":231,"version_start":9,"version_start_type":9,"version_end":232,"version_end_type":233,"fixed_in":9},"lt3_1_1_150400_9_41_1",true,"ecosystem","3.1.1-150400.9.41.1","excluding",{"ecosystem":222,"name":223,"vendor":224,"product":235,"cpe_part":9,"purl_type":226,"purl_namespace":224,"purl_name":235,"source":9,"versions":236},"distribution&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS",[237],{"version":229,"is_range":230,"range_type":231,"version_start":9,"version_start_type":9,"version_end":232,"version_end_type":233,"fixed_in":9},{"ecosystem":222,"name":223,"vendor":224,"product":239,"cpe_part":9,"purl_type":226,"purl_namespace":224,"purl_name":239,"source":9,"versions":240},"distribution&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS",[241],{"version":229,"is_range":230,"range_type":231,"version_start":9,"version_start_type":9,"version_end":232,"version_end_type":233,"fixed_in":9},{"ecosystem":222,"name":223,"vendor":224,"product":243,"cpe_part":9,"purl_type":226,"purl_namespace":224,"purl_name":243,"source":9,"versions":244},"distribution&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS",[245],{"version":229,"is_range":230,"range_type":231,"version_start":9,"version_start_type":9,"version_end":232,"version_end_type":233,"fixed_in":9},{"ecosystem":222,"name":223,"vendor":224,"product":247,"cpe_part":9,"purl_type":226,"purl_namespace":224,"purl_name":247,"source":9,"versions":248},"distribution&distro=SUSE Linux Enterprise Module for Containers 15 SP7",[249],{"version":229,"is_range":230,"range_type":231,"version_start":9,"version_start_type":9,"version_end":232,"version_end_type":233,"fixed_in":9},{"ecosystem":222,"name":223,"vendor":224,"product":251,"cpe_part":9,"purl_type":226,"purl_namespace":224,"purl_name":251,"source":9,"versions":252},"distribution&distro=SUSE Linux Enterprise Server 15 SP4-LTSS",[253],{"version":229,"is_range":230,"range_type":231,"version_start":9,"version_start_type":9,"version_end":232,"version_end_type":233,"fixed_in":9},{"ecosystem":222,"name":223,"vendor":224,"product":255,"cpe_part":9,"purl_type":226,"purl_namespace":224,"purl_name":255,"source":9,"versions":256},"distribution&distro=SUSE Linux Enterprise Server 15 SP5-LTSS",[257],{"version":229,"is_range":230,"range_type":231,"version_start":9,"version_start_type":9,"version_end":232,"version_end_type":233,"fixed_in":9},{"ecosystem":222,"name":223,"vendor":224,"product":259,"cpe_part":9,"purl_type":226,"purl_namespace":224,"purl_name":259,"source":9,"versions":260},"distribution&distro=SUSE Linux Enterprise Server 15 SP6-LTSS",[261],{"version":229,"is_range":230,"range_type":231,"version_start":9,"version_start_type":9,"version_end":232,"version_end_type":233,"fixed_in":9},{"ecosystem":222,"name":223,"vendor":224,"product":263,"cpe_part":9,"purl_type":226,"purl_namespace":224,"purl_name":263,"source":9,"versions":264},"distribution&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4",[265],{"version":229,"is_range":230,"range_type":231,"version_start":9,"version_start_type":9,"version_end":232,"version_end_type":233,"fixed_in":9},{"ecosystem":222,"name":223,"vendor":224,"product":267,"cpe_part":9,"purl_type":226,"purl_namespace":224,"purl_name":267,"source":9,"versions":268},"distribution&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP5",[269],{"version":229,"is_range":230,"range_type":231,"version_start":9,"version_start_type":9,"version_end":232,"version_end_type":233,"fixed_in":9},{"ecosystem":222,"name":223,"vendor":224,"product":271,"cpe_part":9,"purl_type":226,"purl_namespace":224,"purl_name":271,"source":9,"versions":272},"distribution&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP6",[273],{"version":229,"is_range":230,"range_type":231,"version_start":9,"version_start_type":9,"version_end":232,"version_end_type":233,"fixed_in":9}]