🛡️ openSUSE-SU-2026:21251-1 — alloy (CVE-2026-25680 +25 more)
Description
Security update for alloy
This update for alloy fixes the following issues:
Update to version 1.17.0.
Security issues fixed:
- CVE-2026-25680: golang.org/x/net/html: parsing arbitrary HTML can consume excessive CPU time, possibly leading to
denial of service (bsc#1267185).
- CVE-2026-25681: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an
unexpected HTML tree and allows for XSS (bsc#1267185).
- CVE-2026-27136: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an
unexpected HTML tree and allows for XSS (bsc#1267185).
- CVE-2026-33532: yaml: parsing input with deeply nestes collections may throw a
RangeErrordue to a stack overflow
and cause to a denial of service (bsc#1260981).
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation
bypass and privilege escalation (bsc#1266654).
- CVE-2026-39827: golang.org/x/crypto/ssh: authenticated SSH clients that repeatedly open channels which were rejected
by the server can cause unbounded memory growth and a crash (bsc#1266196).
- CVE-2026-39828: golang.org/x/crypto/ssh: permissions discarded when an SSH server authentication callback returns
PartialSuccessError with non-nil permissions (bsc#1266196).
- CVE-2026-39829: golang.org/x/crypto/ssh: unenforced size limits on key parameters by the the RSA and DSA public key
parsers can lead to excessive CPU consumption when processing a crafted public key (bsc#1266196).
- CVE-2026-39830: golang.org/x/crypto/ssh: malicious SSH peers sending unsolicited global request responses can block a
connection's read loop and cause a resource leak (bsc#1266196).
- CVE-2026-39831: golang.org/x/crypto/ssh: missing
User Presenceflag checks in theVerify()method for FIDO/U2F
security key types cause signatures generated without physical touch to be accepted (bsc#1266196).
- CVE-2026-39832: golang.org/x/crypto/ssh: destination restrictions are silently stripped when forwarding keys and
allow for unrestricted use of a key on a remote host (bsc#1266196).
- CVE-2026-39833: golang.org/x/crypto/ssh: in-memory keyring returned by
NewKeyring()silently accepts keys with the
ConfirmBeforeUse constraint but never enforces it (bsc#1266196).
- CVE-2026-39834: golang.org/x/crypto/ssh: writing data larger than 4GB in a single
Writecall on an SSH channel
leads to an integer overflow and an infinite loop that sends empty packets (bsc#1266196).
- CVE-2026-39835: golang.org/x/crypto/ssh: processing of certificates by SSH servers using
CertCheckeras a public
key callback without setting IsUserAuthority or IsHostAuthority can lead to a panic (bsc#1266196).
- CVE-2026-41889: github.com/jackc/pgx/v5/internal/sanitize: use placeholders in dollar-quoted string literals in an
SQL query can lead to a SQL injection (bsc#1265440).
- CVE-2026-42502: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an
unexpected HTML tree and allows for XSS (bsc#1267185).
- CVE-2026-42506: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an
unexpected HTML tree and allows for XSS (bsc#1267185).
- CVE-2026-42508: golang.org/x/crypto/ssh: revoked
SignatureKeys belonging to a CA are not correctly checked for
revocation (bsc#1266196).
- CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via
infinite loops, panics or resource consumption (bsc#1267333).
- CVE-2026-45678: go.opentelemetry.io/obi: Postgres BIND parsing can lead to a panic when malformed payloads are
processed (bsc#1267481).
- CVE-2026-45682: go.opentelemetry.io/obi: keys not deleted by
CappedConcurrentHashMapafter removals allows repeated
connection churn to grow the queue without bound and exhaust heap memory (bsc#1267485).
- CVE-2026-45685: go.opentelemetry.io/obi: MongoDB TCP parser panics on malformed wire messages and causes a DoS
(bsc#1267488).
- CVE-2026-45686: go.opentelemetry.io/obi: integer overflow in memcached text protocol parser can crash the OBI process
and cause denial of service (bsc#1267489).
- CVE-2026-46595: golang.org/x/crypto/ssh: source-address validation is skipped if any other type of callback is passed
other than public key (bsc#1266196).
- CVE-2026-46597: golang.org/x/crypto/ssh: incorrectly placed cast from bytes to int in the AES-GCM packet decoder when
processing specially crafted input can lead to for server-side panic (bsc#1266196).
- CVE-2026-46598: golang.org/x/crypto/ssh:
ed25519.PrivateKeycreated by casting malformed wire bytes due to
processing of certain crafted inputs can lead to panic when used (bsc#1266196).
Other updates and bugfixes:
- Version 1.17.0:
- Features
- Add GraphQL server and
gqlsubcommand. otelcol: Add Nginx receiver.otelcol.exporter.prometheus: Convert class
Affected software
openSUSE-SU-2026:21251-1 is recorded against 1 package.
- alloy (fixed in 1.17.0-160000.1.1)
Timeline and source
Published on 7 July 2026 and last revised on 9 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| alloy | — | 1.17.0-160000.1.1 |
References
Similar Threats
- Unknown openSUSE-SU-2026:11438-1
- Unknown openSUSE-SU-2026:21442-1
- Unknown openSUSE-SU-2026:11165-1
- Unknown openSUSE-SU-2026:11053-1
- Unknown openSUSE-SU-2026:10992-1
Free Vulnerability Check
Is your site affected by openSUSE-SU-2026:21251-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2026:21251-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.