Security update for alloy
This update for alloy fixes the following issues:
Upgrade to version 1.12.1.
Security issues fixed:
(bsc#1251509).
response to a key listing or signing request (bsc#1253609).
html.ParseFragment when processing speciallycrafted input (bsc#1251716).
Other updates and bugfixes:
prometheus.exporter.blackbox, prometheus.exporter.snmp and prometheus.exporter.statsd now use the componentID instead of the hostname as their instance label in their exported metrics.
otelcol.receiver.cloudflare component to receive logs pushed by Cloudflare's LogPushjobs.
database_observability.mysql component:explain_plansexplain_plans collector by defaultdatabase_observability.postgres component:explain_plansquery_samplesquery_samples collector.entries.
query_detailspg_stat_statements with quotes.explain_plans collector by default.server_id when UDP socket used for database connection.otelcol.exporter.googlecloudpubsub community component to export metrics, traces, and logs to Google CloudPub/Sub topic.
structured_metadata_drop stage for loki.process to filter structured metadata.remotecfg service.remotecfg service.stat_statements configuration block to the prometheus.exporter.postgres component to enable selectingboth the query ID and the full SQL statement. The new block includes one option to enable statement selection,
and another to configure the maximum length of the statement text.
loki.process to truncate log entries, label values, and structured_metadata values.u_probe_links & load_probe configuration fields to alloy pyroscope.ebpf to extend configuration ofthe opentelemetry-ebpf-profiler to allow uprobe profiling and dynamic probing.
verbose_mode configuration fields to alloy pyroscope.ebpf to be enable ebpf-profiler verbose mode.file_match block to loki.source.file for built-in file discovery using glob patterns.structured_metadata stage in loki.process to extract labels matching a regularexpression.
[core](https://github.com/open-telemetry/opentelemetry-collector/blob/v0.139.0/CHANGELOG.md)
and
[contrib](https://github.com/open-telemetry/opentelemetry-collector-contrib/blob/v0.139.0/CHANGELOG.md)
changelogs for more details.
mimir.alerts.kubernetes component which discovers AlertmanagerConfig Kubernetes resources and loads theminto a Mimir instance.
stage.windowsevent block in the loki.process component as GA.faro.receiver component, to prevent oneapplication from consuming the rate limit quota of others.
loki.source.(awsfirehose|gcplog|heroku|api) and prometheus.receive_http andpyroscope.receive_http.
SendSIGKILL=no from unit files and recommendations.prometheus.remote_write's WAL by lowering the size of the allocated series storage.labelstore.LabelStore by removing unecessary usage fromprometheus.relabel.
prometheus.exporter.postgres dependency has been updated to v0.18.1.SUSE-SU-2026:0028-1 is recorded against 1 package.
Published on 5 January 2026 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| alloy | — | 1.12.1-150700.15.12.1 |
References
Similar Threats
Free Vulnerability Check
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:0028-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.