🛡️ SUSE-SU-2025:3817-1 — golang-github-prometheus-alertmanager (CVE-2025-47908 +3 more)
Description
Security update 5.1.1 for Multi-Linux Manager Client Tools
This update fixes the following issues:
golang-github-prometheus-alertmanager:
- Update to version 0.28.1 (jsc#PED-13285):
- Improved performance of inhibition rules when using Equal
labels.
- Improve the documentation on escaping in UTF-8 matchers.
- Update alertmanager_config_hash metric help to document the
hash is not cryptographically strong.
- Fix panic in amtool when using --verbose.
- Fix templating of channel field for Rocket.Chat.
- Fix rocketchat_configs written as rocket_configs in docs.
- Fix usage for --enable-feature flag.
- Trim whitespace from OpsGenie API Key.
- Fix Jira project template not rendered when searching for
existing issues.
- Fix subtle bug in JSON/YAML encoding of inhibition rules that
would cause Equal labels to be omitted.
- Fix header for slack_configs in docs.
- Fix weight and wrap of Microsoft Teams notifications.
- Upgrade to version 0.28.0:
- CVE-2025-47908: Bump github.com/rs/cors (bsc#1247748).
- Templating errors in the SNS integration now return an error.
- Adopt log/slog, drop go-kit/log.
- Add a new Microsoft Teams integration based on Flows.
- Add a new Rocket.Chat integration.
- Add a new Jira integration.
- Add support for GOMEMLIMIT, enable it via the feature flag
--enable-feature=auto-gomemlimit.
- Add support for GOMAXPROCS, enable it via the feature flag
--enable-feature=auto-gomaxprocs.
- Add support for limits of silences including the maximum number
of active and pending silences, and the maximum size per
silence (in bytes). You can use the flags
--silences.max-silences and --silences.max-silence-size-bytes
to set them accordingly.
- Muted alerts now show whether they are suppressed or not in
both the /api/v2/alerts endpoint and the Alertmanager UI.
- Upgrade to version 0.27.0:
- API: Removal of all api/v1/ endpoints. These endpoints
now log and return a deprecation message and respond with a
status code of 410.
- UTF-8 Support: Introduction of support for any UTF-8
character as part of label names and matchers.
- Discord Integration: Enforce max length in message.
- Metrics: Introduced the experimental feature flag
--enable-feature=receiver-name-in-metrics to include the
receiver name.
- Metrics: Introduced a new gauge named
alertmanager_inhibition_rules that counts the number of
configured inhibition rules.
- Metrics: Introduced a new counter named
alertmanager_alerts_supressed_total that tracks muted alerts,
it contains a reason label to indicate the source of the mute.
- Discord Integration: Introduced support for webhook_url_file.
- Microsoft Teams Integration: Introduced support for
webhook_url_file.
- Microsoft Teams Integration: Add support for summary.
- Metrics: Notification metrics now support two new values for
the label reason, contextCanceled and contextDeadlineExceeded.
- Email Integration: Contents of auth_password_file are now
trimmed of prefixed and suffixed whitespace.
- amtool: Fixes the error scheme required for webhook url when
using amtool with --alertmanager.url.
- Mixin: Fix AlertmanagerFailedToSendAlerts,
AlertmanagerClusterFailedToSendAlerts, and
AlertmanagerClusterFailedToSendAlerts to make sure they ignore
the reason label.
grafana:
- Update to version 11.5.7:
- Security:
CVE-2025-6023: Fix cross-site-scripting via scripted dashboards
(bsc#1246735)
CVE-2025-6197: Fix open redirect in organization switching
(bsc#1246736)
- Bug fixes:
Azure: Fix legend formatting.
Azure: Fix resource name determination in template variable
queries.
- Update to version 11.5.6:
CVE-2025-3415: Fix exposure of DingDing alerting integration
URL to Viewer level users (bsc#1245302)
mgr-push:
- Version 5.1.4-0
- Use absolute paths when invoking external commands
- Fix syntax error in changelog
python-defusedxml:
- Update to 0.6.0
- Increase test coverage.
- Add badges to README.
- Test on Python 3.7 stable and 3.8-dev
- Drop support for Python 3.4
- No longer pass *html* argument to XMLParse. It has been deprecated and
ignored for a long time. The DefusedXMLParser still takes a html argument.
A deprecation warning is issued when the argument is False and a TypeError
when it's True.
- defusedxml now fails early when pyexpat stdlib module is not available or
broken.
- defusedxml.ElementTree.__all__ now lists ParseError as public attribute.
- The defusedxml.ElementTree and defusedxml.cElementTree modules had a typo
and used XMLParse instead of XMLParser as an alias for DefusedXMLParser.
Both the old and fixed name are now available.
- Remove superfluous devel dependency for noarch package
- Fix source url.
- Update to 5.0
- Add compatibility with Python 3.6
- Drop support for
Affected software
SUSE-SU-2025:3817-1 is recorded against 9 packages.
- golang-github-prometheus-alertmanager (fixed in 0.28.1-120002.4.3.2)
- grafana (fixed in 11.5.7-120002.4.3.2)
- mgr-push (fixed in 5.1.4-120002.3.3.3)
- multi-linux-managertools-sle-release (fixed in 12-120002.1.3.2)
- python-defusedxml (fixed in 0.6.0-120002.1.3.1)
- rhnlib (fixed in 5.1.3-120002.3.3.1)
- spacecmd (fixed in 5.1.11-120002.3.3.2)
- spacewalk-client-tools (fixed in 5.1.7-120002.3.3.2)
- supportutils-plugin-susemanager-client (fixed in 5.1.4-120002.3.3.1)
Timeline and source
Published on 28 October 2025 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| golang-github-prometheus-alertmanager | — | 0.28.1-120002.4.3.2 |
| grafana | — | 11.5.7-120002.4.3.2 |
| mgr-push | — | 5.1.4-120002.3.3.3 |
| multi-linux-managertools-sle-release | — | 12-120002.1.3.2 |
| python-defusedxml | — | 0.6.0-120002.1.3.1 |
| rhnlib | — | 5.1.3-120002.3.3.1 |
| spacecmd | — | 5.1.11-120002.3.3.2 |
| spacewalk-client-tools | — | 5.1.7-120002.3.3.2 |
| supportutils-plugin-susemanager-client | — | 5.1.4-120002.3.3.1 |
References
Similar Threats
- Unknown openSUSE-SU-2026:21157-1
- Unknown openSUSE-SU-2026:21136-1
- Unknown openSUSE-SU-2026:11011-1
- Unknown openSUSE-SU-2026:10612-1
- Unknown openSUSE-SU-2025:15178-1
Free Vulnerability Check
Is your site affected by SUSE-SU-2025:3817-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:3817-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.