SUSE-SU-2026:1008-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20261008-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:1008-1
Upstream
  • CVE-2025-61140
Related
Published
2026-03-25T10:07:27Z
Modified
2026-03-26T09:00:08.238482Z
Summary
Security update for Prometheus
Details

This update for Prometheus fixes the following issues:

golang-github-prometheus-alertmanager, golang-github-prometheus-node_exporter:

  • Internal changes to fix build issues with no impact for customers

golang-github-prometheus-prometheus:

  • Security issues fixed:

    • CVE-2026-27606: Fixed arbitrary file write via path traversal in rollup (bsc#1258893)
    • CVE-2026-25547: Fixed unbounded brace range expansion leading to excessive CPU and memory consumption (bsc#1257841)
    • CVE-2026-1615, CVE-2025-61140 The old web UI is no longer built due to security issues (bsc#1257897, bsc#1257442)
    • CVE-2025-13465: Bump lodash package to version 4.17.23 to fix prototype pollution vulnerability (bsc#1257329)
    • CVE-2025-12816: Interpretation conflict vulnerability allowing bypassing cryptographic verifications (bsc#1255588)
  • Version update from 2.53.4 to 3.5.0 with the following highlighted changes (jsc#PED-13824):

    • Modernized Interface: Introduced a brand-new UI
    • Enhanced Cloud and Auth: Added unified AWS service discovery (EC2, ECS, Lightsail) and Azure Workload Identity support for more secure, native cloudauthentication.
    • Performance Standards: Fully integrated OpenTelemetry (OTLP) ingestion and moved Native Histograms from experimental to a stable feature.
    • Advanced Data Export: Rolled out Remote Write 2.0, offering better performance and metadata handling when sending data to external systems.
    • Query Power: Added new PromQL functions (like firstovertime and lastovertime) and optimization for grouping operations.
    • Better Visibility: The UI now displays detailed relabeling steps, scrape intervals, and timeouts, making it easier to troubleshoot why targets aren't reporting correctly.
    • Critical Fixes: Resolved significant memory leaks related to query logging and fixed bugs where targets were accidentally being scraped multiple times.
References

Affected packages

openSUSE:Leap 15.6
golang-github-prometheus-alertmanager

Package

Name
golang-github-prometheus-alertmanager
Purl
pkg:rpm/opensuse/golang-github-prometheus-alertmanager&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.28.1-150100.4.31.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-alertmanager": "0.28.1-150100.4.31.1",
            "golang-github-prometheus-node_exporter": "1.9.1-150100.3.38.1",
            "firewalld-prometheus-config": "0.1-150100.4.29.1",
            "golang-github-prometheus-prometheus": "3.5.0-150100.4.29.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/opensuse/golang-github-prometheus-node_exporter&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-150100.3.38.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-alertmanager": "0.28.1-150100.4.31.1",
            "golang-github-prometheus-node_exporter": "1.9.1-150100.3.38.1",
            "firewalld-prometheus-config": "0.1-150100.4.29.1",
            "golang-github-prometheus-prometheus": "3.5.0-150100.4.29.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
golang-github-prometheus-prometheus

Package

Name
golang-github-prometheus-prometheus
Purl
pkg:rpm/opensuse/golang-github-prometheus-prometheus&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.0-150100.4.29.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-alertmanager": "0.28.1-150100.4.31.1",
            "golang-github-prometheus-node_exporter": "1.9.1-150100.3.38.1",
            "firewalld-prometheus-config": "0.1-150100.4.29.1",
            "golang-github-prometheus-prometheus": "3.5.0-150100.4.29.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-150100.3.38.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-node_exporter": "1.9.1-150100.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-150100.3.38.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-node_exporter": "1.9.1-150100.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-150100.3.38.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-node_exporter": "1.9.1-150100.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-150100.3.38.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-node_exporter": "1.9.1-150100.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
SUSE:Linux Enterprise Module for Basesystem 15 SP7
golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-150100.3.38.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-node_exporter": "1.9.1-150100.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
SUSE:Linux Enterprise Module for Package Hub 15 SP7
golang-github-prometheus-alertmanager

Package

Name
golang-github-prometheus-alertmanager
Purl
pkg:rpm/suse/golang-github-prometheus-alertmanager&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.28.1-150100.4.31.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-alertmanager": "0.28.1-150100.4.31.1",
            "golang-github-prometheus-prometheus": "3.5.0-150100.4.29.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
golang-github-prometheus-prometheus

Package

Name
golang-github-prometheus-prometheus
Purl
pkg:rpm/suse/golang-github-prometheus-prometheus&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.0-150100.4.29.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-alertmanager": "0.28.1-150100.4.31.1",
            "golang-github-prometheus-prometheus": "3.5.0-150100.4.29.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-150100.3.38.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-node_exporter": "1.9.1-150100.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-150100.3.38.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-node_exporter": "1.9.1-150100.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-150100.3.38.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-node_exporter": "1.9.1-150100.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-150100.3.38.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-node_exporter": "1.9.1-150100.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-150100.3.38.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-node_exporter": "1.9.1-150100.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-150100.3.38.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-node_exporter": "1.9.1-150100.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
SUSE:Manager Client Tools 15
golang-github-prometheus-alertmanager

Package

Name
golang-github-prometheus-alertmanager
Purl
pkg:rpm/suse/golang-github-prometheus-alertmanager&distro=SUSE%20Manager%20Client%20Tools%2015

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.28.1-150100.4.31.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-alertmanager": "0.28.1-150100.4.31.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"
SUSE:Manager Client Tools for SLE Micro 5
golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Manager%20Client%20Tools%20for%20SLE%20Micro%205

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-150100.3.38.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-node_exporter": "1.9.1-150100.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1008-1.json"