🛡️ openSUSE-SU-2026:21136-1 — golang-github-prometheus-alertmanager (CVE-2025-47908 +2 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for golang-github-prometheus-alertmanager

This update for golang-github-prometheus-alertmanager fixes the following issues:

Changes in golang-github-prometheus-alertmanager:

  • Update to version 0.28.1 (jsc#PED-13285):
  • Improved performance of inhibition rules when using Equal

labels.

  • Improve the documentation on escaping in UTF-8 matchers.
  • Update alertmanager_config_hash metric help to document the

hash is not cryptographically strong.

  • Fix panic in amtool when using --verbose.
  • Fix templating of channel field for Rocket.Chat.
  • Fix rocketchat_configs written as rocket_configs in docs.
  • Fix usage for --enable-feature flag.
  • Trim whitespace from OpsGenie API Key.
  • Fix Jira project template not rendered when searching for

existing issues.

  • Fix subtle bug in JSON/YAML encoding of inhibition rules that

would cause Equal labels to be omitted.

  • Fix header for slack_configs in docs.
  • Fix weight and wrap of Microsoft Teams notifications.
  • Upgrade to version 0.28.0:
  • CVE-2025-47908: Bump github.com/rs/cors (bsc#1247748).
  • Templating errors in the SNS integration now return an error.
  • Adopt log/slog, drop go-kit/log.
  • Add a new Microsoft Teams integration based on Flows.
  • Add a new Rocket.Chat integration.
  • Add a new Jira integration.
  • Add support for GOMEMLIMIT, enable it via the feature flag

--enable-feature=auto-gomemlimit.

  • Add support for GOMAXPROCS, enable it via the feature flag

--enable-feature=auto-gomaxprocs.

  • Add support for limits of silences including the maximum number

of active and pending silences, and the maximum size per

silence (in bytes). You can use the flags

--silences.max-silences and --silences.max-silence-size-bytes

to set them accordingly.

  • Muted alerts now show whether they are suppressed or not in

both the /api/v2/alerts endpoint and the Alertmanager UI.

  • Upgrade to version 0.27.0:
  • API: Removal of all api/v1/ endpoints. These endpoints

now log and return a deprecation message and respond with a

status code of 410.

  • UTF-8 Support: Introduction of support for any UTF-8

character as part of label names and matchers.

  • Discord Integration: Enforce max length in message.
  • Metrics: Introduced the experimental feature flag

--enable-feature=receiver-name-in-metrics to include the

receiver name.

  • Metrics: Introduced a new gauge named

alertmanager_inhibition_rules that counts the number of

configured inhibition rules.

  • Metrics: Introduced a new counter named

alertmanager_alerts_supressed_total that tracks muted alerts,

it contains a reason label to indicate the source of the mute.

  • Discord Integration: Introduced support for webhook_url_file.
  • Microsoft Teams Integration: Introduced support for

webhook_url_file.

  • Microsoft Teams Integration: Add support for summary.
  • Metrics: Notification metrics now support two new values for

the label reason, contextCanceled and contextDeadlineExceeded.

  • Email Integration: Contents of auth_password_file are now

trimmed of prefixed and suffixed whitespace.

  • amtool: Fixes the error scheme required for webhook url when

using amtool with --alertmanager.url.

  • Mixin: Fix AlertmanagerFailedToSendAlerts,

AlertmanagerClusterFailedToSendAlerts, and

AlertmanagerClusterFailedToSendAlerts to make sure they ignore

the reason label.

  • Security:
  • Fix proxy bypassing using IPv6 zone IDs

(CVE-2025-22870, bsc#1238686)

  • Fix HTTP/2 CONTINUATION flood in net/http

(CVE-2023-45288, bsc#1236516)

  • Add 0002-Bump-x-net.patch

Affected software

openSUSE-SU-2026:21136-1 is recorded against 1 package.

  • golang-github-prometheus-alertmanager (fixed in 0.28.1-bp160.1.1)

Timeline and source

Published on 18 June 2026 and last revised on 30 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-06-18
Updated 2026-08-20
Modified 2026-06-30
Fix URL N/A

Affected Packages

Software From version Fixed in
golang-github-prometheus-alertmanager 0.28.1-bp160.1.1

Free Vulnerability Check

Is your site affected by openSUSE-SU-2026:21136-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2026:21136-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2026