SUSE-SU-2026:3713-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263713-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3713-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:3713-1
Upstream
CVE (8)
Related
Published
2026-08-24T02:53:30Z
Modified
2026-08-24T17:31:12Z
Summary
Security update for Multi-Linux Manager Client Tools - Monitoring stack
Details

This update fixes the following issues:

golang-github-prometheus-alertmanager:

  • CVE-2026-39821: Fix validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266615)

golang-github-prometheus-prometheus updated from version 3.5.3 to 3.5.4:

  • Security fixes:

    • CVE-2026-39882: Fix reading unbounded HTTP response bodies by bumping OpenTelemetry to 1.43.0 (bsc#1274221)
    • CVE-2026-33244: Fix improper neutralization of the HTTP Location header value in react-router (bsc#1267416)
    • CVE-2026-13149: Prevent potential DoS by bumping brace-expansion to version 5.0.7 (bsc#1269917)
    • CVE-2026-33814: Fix infinite loop in HTTP/2 transport (bsc#1265827)
  • Other bugs fixed and changes:

    • STACKIT SD: Fix secrets being exposed in plaintext via /-/config endpoint
    • Chore: Bump golang.org/x/net to version 0.55.0

grafana updated from version 11.6.14+security04 to version 12.4.5:

Security fixes:

  • CVE-2026-39882: Prevent memory exhaustion DoS in OpenTelemetry OTLP HTTP exporters (bsc#1274217)
  • CVE-2026-33382: Limit the size of the request body before processing it at several Grafana API endpoints (bsc#1271331)
  • CVE-2025-12141: Fixed information leakage in Grafana Alerting (bsc#1262187)
  • CVE-2026-41607: Fix potential information disclosure in Apache Thrift (bsc#1263272)

Breaking chahnges introduced in version 12.0.0:

  • BREAKING: Removed AngularJS and all deprecated UI Extensions APIs.
  • BREAKING: Enforced stricter version compatibility checks in plugin CLI install commands.
  • BREAKING: Enabled the failWrongDSUID feature flag by default, which rejects data sources with incorrect UIDs.

Other changes introduced from version 11.6.14+security04 to version 12.4.5 (jsc#PED-16512):

  • Add Legal-Review-Notice (bsc#1271327)
  • Datasources: return 400 when payload UID does not match URL UID in PUT /api/datasources/uid/:uid
  • Analytics: Keep internal dashboard id.
  • Reporting: Correctly apply appSubURL to report settings requests
  • Alerting: Document Grafana HA Alertmanager cluster metrics prefix change.
  • Dependency updates to core plugins and UI libraries.
  • Updates to data source provisioning and dashboard schemas.
  • Introduced dynamic dashboards in public preview.
  • Added a new side toolbar that replaces the second top toolbar to provide additional vertical space.
  • Added the ability to create dashboards from templates using sample data.
  • Revamped the gauge visualization with rounded bars, configurable bar thickness, and endpoint markers.
  • Added support to map one variable to multiple values.
  • Released a completely redesigned logs visualization.
  • Added the ability to export dashboards directly as PNG images.
  • Introduced an interactive learning experience within the Grafana UI.
  • Added a Switch template variable type to quickly toggle between values in queries.
  • Added functionality to style table cells using CSS properties via the field cell option.
  • Added support for Entra Workload Identity to enhance authentication capabilities with federated credentials.
  • Redesigned the alert rule list page.
  • Renamed Mute Timings to Active Time Intervals in Grafana Alerting.
  • Added support for Service Account Impersonation in the BigQuery data source.
  • Introduced the Grafana Advisor in public preview.
  • Introduced a new dashboard schema to replace the original single grid layout.
  • MIGRATION: Triggered a full-table rewrite for the annotation table, which may temporarily increase disk usage.
References

Affected packages

SUSE:Multi Linux Manager Tools SLE-15
golang-github-prometheus-alertmanager

Package

Name
golang-github-prometheus-alertmanager
Purl
pkg:rpm/suse/golang-github-prometheus-alertmanager&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.28.1-150002.4.14.1

Ecosystem specific

{
    "binaries":  [
        {
            "firewalld-prometheus-config":  "0.1-150002.3.16.1",
            "golang-github-prometheus-alertmanager":  "0.28.1-150002.4.14.1",
            "golang-github-prometheus-prometheus":  "3.5.4-150002.3.16.1",
            "grafana":  "12.4.5-150002.4.24.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3713-1.json"
golang-github-prometheus-prometheus

Package

Name
golang-github-prometheus-prometheus
Purl
pkg:rpm/suse/golang-github-prometheus-prometheus&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.5.4-150002.3.16.1

Ecosystem specific

{
    "binaries":  [
        {
            "firewalld-prometheus-config":  "0.1-150002.3.16.1",
            "golang-github-prometheus-alertmanager":  "0.28.1-150002.4.14.1",
            "golang-github-prometheus-prometheus":  "3.5.4-150002.3.16.1",
            "grafana":  "12.4.5-150002.4.24.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3713-1.json"
grafana

Package

Name
grafana
Purl
pkg:rpm/suse/grafana&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
12.4.5-150002.4.24.1

Ecosystem specific

{
    "binaries":  [
        {
            "firewalld-prometheus-config":  "0.1-150002.3.16.1",
            "golang-github-prometheus-alertmanager":  "0.28.1-150002.4.14.1",
            "golang-github-prometheus-prometheus":  "3.5.4-150002.3.16.1",
            "grafana":  "12.4.5-150002.4.24.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3713-1.json"