🛡️ openSUSE-SU-2026:21251-1 — alloy (CVE-2026-25680 +25 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for alloy

This update for alloy fixes the following issues:

Update to version 1.17.0.

Security issues fixed:

  • CVE-2026-25680: golang.org/x/net/html: parsing arbitrary HTML can consume excessive CPU time, possibly leading to

denial of service (bsc#1267185).

  • CVE-2026-25681: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an

unexpected HTML tree and allows for XSS (bsc#1267185).

  • CVE-2026-27136: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an

unexpected HTML tree and allows for XSS (bsc#1267185).

  • CVE-2026-33532: yaml: parsing input with deeply nestes collections may throw a RangeError due to a stack overflow

and cause to a denial of service (bsc#1260981).

  • CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation

bypass and privilege escalation (bsc#1266654).

  • CVE-2026-39827: golang.org/x/crypto/ssh: authenticated SSH clients that repeatedly open channels which were rejected

by the server can cause unbounded memory growth and a crash (bsc#1266196).

  • CVE-2026-39828: golang.org/x/crypto/ssh: permissions discarded when an SSH server authentication callback returns

PartialSuccessError with non-nil permissions (bsc#1266196).

  • CVE-2026-39829: golang.org/x/crypto/ssh: unenforced size limits on key parameters by the the RSA and DSA public key

parsers can lead to excessive CPU consumption when processing a crafted public key (bsc#1266196).

  • CVE-2026-39830: golang.org/x/crypto/ssh: malicious SSH peers sending unsolicited global request responses can block a

connection's read loop and cause a resource leak (bsc#1266196).

  • CVE-2026-39831: golang.org/x/crypto/ssh: missing User Presence flag checks in the Verify() method for FIDO/U2F

security key types cause signatures generated without physical touch to be accepted (bsc#1266196).

  • CVE-2026-39832: golang.org/x/crypto/ssh: destination restrictions are silently stripped when forwarding keys and

allow for unrestricted use of a key on a remote host (bsc#1266196).

  • CVE-2026-39833: golang.org/x/crypto/ssh: in-memory keyring returned by NewKeyring() silently accepts keys with the

ConfirmBeforeUse constraint but never enforces it (bsc#1266196).

  • CVE-2026-39834: golang.org/x/crypto/ssh: writing data larger than 4GB in a single Write call on an SSH channel

leads to an integer overflow and an infinite loop that sends empty packets (bsc#1266196).

  • CVE-2026-39835: golang.org/x/crypto/ssh: processing of certificates by SSH servers using CertChecker as a public

key callback without setting IsUserAuthority or IsHostAuthority can lead to a panic (bsc#1266196).

  • CVE-2026-41889: github.com/jackc/pgx/v5/internal/sanitize: use placeholders in dollar-quoted string literals in an

SQL query can lead to a SQL injection (bsc#1265440).

  • CVE-2026-42502: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an

unexpected HTML tree and allows for XSS (bsc#1267185).

  • CVE-2026-42506: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an

unexpected HTML tree and allows for XSS (bsc#1267185).

  • CVE-2026-42508: golang.org/x/crypto/ssh: revoked SignatureKeys belonging to a CA are not correctly checked for

revocation (bsc#1266196).

  • CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via

infinite loops, panics or resource consumption (bsc#1267333).

  • CVE-2026-45678: go.opentelemetry.io/obi: Postgres BIND parsing can lead to a panic when malformed payloads are

processed (bsc#1267481).

  • CVE-2026-45682: go.opentelemetry.io/obi: keys not deleted by CappedConcurrentHashMap after removals allows repeated

connection churn to grow the queue without bound and exhaust heap memory (bsc#1267485).

  • CVE-2026-45685: go.opentelemetry.io/obi: MongoDB TCP parser panics on malformed wire messages and causes a DoS

(bsc#1267488).

  • CVE-2026-45686: go.opentelemetry.io/obi: integer overflow in memcached text protocol parser can crash the OBI process

and cause denial of service (bsc#1267489).

  • CVE-2026-46595: golang.org/x/crypto/ssh: source-address validation is skipped if any other type of callback is passed

other than public key (bsc#1266196).

  • CVE-2026-46597: golang.org/x/crypto/ssh: incorrectly placed cast from bytes to int in the AES-GCM packet decoder when

processing specially crafted input can lead to for server-side panic (bsc#1266196).

  • CVE-2026-46598: golang.org/x/crypto/ssh: ed25519.PrivateKey created by casting malformed wire bytes due to

processing of certain crafted inputs can lead to panic when used (bsc#1266196).

Other updates and bugfixes:

  • Version 1.17.0:
  • Features
  • Add GraphQL server and gql subcommand.
  • otelcol: Add Nginx receiver.
  • otelcol.exporter.prometheus: Convert class

Affected software

openSUSE-SU-2026:21251-1 is recorded against 1 package.

  • alloy (fixed in 1.17.0-160000.1.1)

Timeline and source

Published on 7 July 2026 and last revised on 9 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-07
Updated 2026-08-20
Modified 2026-07-09
Fix URL N/A

Affected Packages

Software From version Fixed in
alloy 1.17.0-160000.1.1

References

Free Vulnerability Check

Is your site affected by openSUSE-SU-2026:21251-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2026:21251-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2026