SUSE-SU-2026:1951-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20261951-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1951-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:1951-1
Upstream
CVE (2)
Related
Published
2026-05-18T07:52:39Z
Modified
2026-05-19T08:45:06Z
Summary
Security update for zypper-docker
Details

This update for zypper-docker fixes the following issues

  • CVE-2026-2808: github.com/hashicorp/consul: unvalidated user-supplied file paths can lead to arbitrary file reads through the Vault Kubernetes authentication provider (bsc#1259563).
  • CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo- header (bsc#1260086).

Changes for zypper-docker:

  • Bump to version 2.0.2
  • update vendor provided docker to v28.5.2
  • update go sources to use new docker api
  • update vendor directory to reflect docker update
  • Bump to version 2.0.1
  • Fix golint import path
  • migrate to go 1.11 module
  • ci: use registry.opensuse.org
References

Affected packages