🛡️ SUSE-SU-2025:3817-1 — golang-github-prometheus-alertmanager (CVE-2025-47908 +3 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update 5.1.1 for Multi-Linux Manager Client Tools

This update fixes the following issues:

golang-github-prometheus-alertmanager:

  • Update to version 0.28.1 (jsc#PED-13285):
  • Improved performance of inhibition rules when using Equal

labels.

  • Improve the documentation on escaping in UTF-8 matchers.
  • Update alertmanager_config_hash metric help to document the

hash is not cryptographically strong.

  • Fix panic in amtool when using --verbose.
  • Fix templating of channel field for Rocket.Chat.
  • Fix rocketchat_configs written as rocket_configs in docs.
  • Fix usage for --enable-feature flag.
  • Trim whitespace from OpsGenie API Key.
  • Fix Jira project template not rendered when searching for

existing issues.

  • Fix subtle bug in JSON/YAML encoding of inhibition rules that

would cause Equal labels to be omitted.

  • Fix header for slack_configs in docs.
  • Fix weight and wrap of Microsoft Teams notifications.
  • Upgrade to version 0.28.0:
  • CVE-2025-47908: Bump github.com/rs/cors (bsc#1247748).
  • Templating errors in the SNS integration now return an error.
  • Adopt log/slog, drop go-kit/log.
  • Add a new Microsoft Teams integration based on Flows.
  • Add a new Rocket.Chat integration.
  • Add a new Jira integration.
  • Add support for GOMEMLIMIT, enable it via the feature flag

--enable-feature=auto-gomemlimit.

  • Add support for GOMAXPROCS, enable it via the feature flag

--enable-feature=auto-gomaxprocs.

  • Add support for limits of silences including the maximum number

of active and pending silences, and the maximum size per

silence (in bytes). You can use the flags

--silences.max-silences and --silences.max-silence-size-bytes

to set them accordingly.

  • Muted alerts now show whether they are suppressed or not in

both the /api/v2/alerts endpoint and the Alertmanager UI.

  • Upgrade to version 0.27.0:
  • API: Removal of all api/v1/ endpoints. These endpoints

now log and return a deprecation message and respond with a

status code of 410.

  • UTF-8 Support: Introduction of support for any UTF-8

character as part of label names and matchers.

  • Discord Integration: Enforce max length in message.
  • Metrics: Introduced the experimental feature flag

--enable-feature=receiver-name-in-metrics to include the

receiver name.

  • Metrics: Introduced a new gauge named

alertmanager_inhibition_rules that counts the number of

configured inhibition rules.

  • Metrics: Introduced a new counter named

alertmanager_alerts_supressed_total that tracks muted alerts,

it contains a reason label to indicate the source of the mute.

  • Discord Integration: Introduced support for webhook_url_file.
  • Microsoft Teams Integration: Introduced support for

webhook_url_file.

  • Microsoft Teams Integration: Add support for summary.
  • Metrics: Notification metrics now support two new values for

the label reason, contextCanceled and contextDeadlineExceeded.

  • Email Integration: Contents of auth_password_file are now

trimmed of prefixed and suffixed whitespace.

  • amtool: Fixes the error scheme required for webhook url when

using amtool with --alertmanager.url.

  • Mixin: Fix AlertmanagerFailedToSendAlerts,

AlertmanagerClusterFailedToSendAlerts, and

AlertmanagerClusterFailedToSendAlerts to make sure they ignore

the reason label.

grafana:

  • Update to version 11.5.7:
  • Security:

CVE-2025-6023: Fix cross-site-scripting via scripted dashboards

(bsc#1246735)

CVE-2025-6197: Fix open redirect in organization switching

(bsc#1246736)

  • Bug fixes:

Azure: Fix legend formatting.

Azure: Fix resource name determination in template variable

queries.

  • Update to version 11.5.6:

CVE-2025-3415: Fix exposure of DingDing alerting integration

URL to Viewer level users (bsc#1245302)

mgr-push:

  • Version 5.1.4-0
  • Use absolute paths when invoking external commands
  • Fix syntax error in changelog

python-defusedxml:

  • Update to 0.6.0
  • Increase test coverage.
  • Add badges to README.
  • Test on Python 3.7 stable and 3.8-dev
  • Drop support for Python 3.4
  • No longer pass *html* argument to XMLParse. It has been deprecated and

ignored for a long time. The DefusedXMLParser still takes a html argument.

A deprecation warning is issued when the argument is False and a TypeError

when it's True.

  • defusedxml now fails early when pyexpat stdlib module is not available or

broken.

  • defusedxml.ElementTree.__all__ now lists ParseError as public attribute.
  • The defusedxml.ElementTree and defusedxml.cElementTree modules had a typo

and used XMLParse instead of XMLParser as an alias for DefusedXMLParser.

Both the old and fixed name are now available.

  • Remove superfluous devel dependency for noarch package
  • Fix source url.
  • Update to 5.0
  • Add compatibility with Python 3.6
  • Drop support for

Affected software

SUSE-SU-2025:3817-1 is recorded against 9 packages.

  • golang-github-prometheus-alertmanager (fixed in 0.28.1-120002.4.3.2)
  • grafana (fixed in 11.5.7-120002.4.3.2)
  • mgr-push (fixed in 5.1.4-120002.3.3.3)
  • multi-linux-managertools-sle-release (fixed in 12-120002.1.3.2)
  • python-defusedxml (fixed in 0.6.0-120002.1.3.1)
  • rhnlib (fixed in 5.1.3-120002.3.3.1)
  • spacecmd (fixed in 5.1.11-120002.3.3.2)
  • spacewalk-client-tools (fixed in 5.1.7-120002.3.3.2)
  • supportutils-plugin-susemanager-client (fixed in 5.1.4-120002.3.3.1)

Timeline and source

Published on 28 October 2025 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-10-28
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
golang-github-prometheus-alertmanager 0.28.1-120002.4.3.2
grafana 11.5.7-120002.4.3.2
mgr-push 5.1.4-120002.3.3.3
multi-linux-managertools-sle-release 12-120002.1.3.2
python-defusedxml 0.6.0-120002.1.3.1
rhnlib 5.1.3-120002.3.3.1
spacecmd 5.1.11-120002.3.3.2
spacewalk-client-tools 5.1.7-120002.3.3.2
supportutils-plugin-susemanager-client 5.1.4-120002.3.3.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:3817-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:3817-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2025