🛡️ openSUSE-SU-2026:21262-1 — hauler (CVE-2026-48702 +6 more)
Description
Security update for hauler
This update for hauler fixes the following issues:
Changes in hauler:
- update to 2.0.1 (bsc#1269433, CVE-2026-48702):
- bump go to 1.26.4 to squash CVE noise
- Full v2 Release notes: https://github.com/hauler-
dev/hauler/releases/tag/v2.0.0
- update to 2.0.0:
v2.0.0is a major release. It replaces Hauler's entire
OCI plumbing... the ORAS v1 dependency and the in-house
cosign fork with a native containerd based implementation,
drops the deprecated v1alpha1 API, and layers on a
meaningful set of new capabilities and reliability fixes on
top of that new foundation.
- Removed the ORAS v1 dependency - push/pull is now driven
directly by containerd's docker resolver and `google/go-
containerregistry, new pkg/content/registry.go`
(RegistryTarget) and pkg/content/types.go (Target
interface, IoContentWriter) replaces what ORAS used to own.
- Removed the hauler-maintained cosign fork -
pkg/cosign
is now a thin verify only wrapper around upstream
sigstore/cosign/v3. Images are added through a native
s.AddImage() path in pkg/store
- Added OCI 1.1 Referrers support - signatures,
attestations, and SBOMs are discovered both via the classic
cosign tag convention (sha256-.sig / .att / .sbom) and
the modern Referrers API, then correctly through the OCI
layout
- update x/net to v0.55.0 (bsc#1266602, CVE-2026-39821,
bsc#1267150, CVE-2026-25680, CVE-2026-42502, CVE-2026-27136,
CVE-2026-25681, CVE-2026-42506)
Affected software
openSUSE-SU-2026:21262-1 is recorded against 1 package.
- hauler (fixed in 2.0.1-bp160.1.1)
Timeline and source
Published on 6 July 2026 and last revised on 9 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| hauler | — | 2.0.1-bp160.1.1 |
References
Similar Threats
- Unknown openSUSE-SU-2026:21433-1
- Unknown openSUSE-SU-2026:11154-1
- Unknown openSUSE-SU-2026:10933-1
- Unknown openSUSE-SU-2026:10875-1
- Unknown openSUSE-SU-2026:10843-1
Free Vulnerability Check
Is your site affected by openSUSE-SU-2026:21262-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2026:21262-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.