openSUSE-SU-2026:21481-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21481-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21481-1
Upstream
CVE (9)
Related
Published
2026-07-30T04:41:29Z
Modified
2026-08-03T02:10:47Z
Summary
Security update for vexctl
Details

This update for vexctl fixes the following issues:

  • CVE-2024-45337: golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (bsc#1234486).
  • CVE-2025-22868: golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239186).
  • CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239323).
  • CVE-2025-22870: golang.org/x/net/proxy: proxy bypass using IPv6 zone IDs (bsc#1238683).
  • CVE-2025-27144: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: Go JOSE's Parsing Vulnerable to Denial of Service (bsc#1237611).
  • CVE-2025-30204: github.com/golang-jwt/jwt/v4: jwt-go allows excessive memory allocation during header parsing (bsc#1240444).
  • CVE-2025-58181: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253802).
  • CVE-2026-22772: github.com/sigstore/fulcio: bypass MetaIssuer URL validation bypass can trigger SSRF to arbitrary internal services (bsc#1256535).
  • CVE-2026-24137: github.com/sigstore/sigstore/pkg/tuf: legacy TUF client allows for arbitrary file writes with target cache path traversal (bsc#1257138).

Changes for vexctl:

  • Update to version 0.4.4+git20.5d61136:
  • build(deps): Bump github.com/sigstore/cosign/v2
  • build(deps): Bump actions/setup-go from 6.5.0 to 7.0.0
  • build(deps): Bump the all group across 1 directory with 5 updates
  • build(deps): Bump github.com/sigstore/rekor in the all group
  • build(deps): Bump the all group with 4 updates
  • build(deps): Bump github.com/google/go-containerregistry
  • build(deps): Bump actions/setup-go from 6.4.0 to 6.5.0 in the all group
  • build(deps): Bump the all group across 1 directory with 2 updates
  • build(deps): Bump actions/checkout from 6.0.3 to 7.0.0
  • build(deps): Bump chainguard-dev/actions in the all group
  • Update to version 0.4.4:
  • fix signature duplication
  • fix lints
  • housekeeping - deps update and ci cleanup
  • build(deps): Bump the all group with 2 updates
  • build(deps): Bump github.com/sigstore/sigstore in the all group
  • build(deps): Bump golangci/golangci-lint-action in the all group
  • Update to version 0.4.1+git147.b7e6ef0:
  • build(deps): Bump goreleaser/goreleaser-action in the all group
  • Bump sigstore/cosign-installer from 4.1.1 to 4.1.2 in the all group
  • Bump chainguard-dev/actions from 1.6.17 to 1.6.19 in the all group
  • Bump chainguard-dev/actions from 1.6.16 to 1.6.17 in the all group
  • Bump github.com/package-url/packageurl-go in the all group
  • Bump the all group with 2 updates
  • Update to version 0.4.1+git133.efecaf7:
  • Bump github.com/secure-systems-lab/go-securesystemslib
  • Update to version 0.4.1+git129.c7f3066:
  • Bump github.com/google/go-containerregistry in the all group
  • Bump github.com/sigstore/timestamp-authority/v2 from 2.0.3 to 2.0.6
  • Bump softprops/action-gh-release from 2.6.1 to 3.0.0
  • Bump chainguard-dev/actions from 1.6.13 to 1.6.14 in the all group
  • Bump actions/upload-artifact from 7.0.0 to 7.0.1 in the all group
  • Bump github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3 in the all group
  • Bump kubernetes-sigs/release-actions in the all group
  • Bump github.com/in-toto/in-toto-golang from 0.9.0 to 0.10.0
  • Bump the all group across 1 directory with 2 updates
  • Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4
  • fix(add): allow add without --product flag
  • Use gomod version, bump linter
  • Port vexctl to intoto/attestation
  • Bump the all group across 1 directory with 5 updates
  • Bump google.golang.org/grpc from 1.78.0 to 1.79.3
  • Update to version 0.4.1+git96.558125d:
  • Bump the all group across 1 directory with 3 updates
  • Bump chainguard-dev/actions from 1.6.5 to 1.6.6 in the all group
  • Bump github.com/google/go-containerregistry from 0.20.7 to 0.21.0
  • Bump actions/upload-artifact from 6.0.0 to 7.0.0
  • Bump goreleaser/goreleaser-action from 6.4.0 to 7.0.0
  • Bump chainguard-dev/actions from 1.6.2 to 1.6.4 in the all group
  • Update to version 0.4.1+git78.f951e3a:
  • Bump chainguard-dev/actions from 1.6.1 to 1.6.2 in the all group
  • Update to version 0.4.1+git76.10d7a2e:
  • Bump chainguard-dev/actions from 1.6.0 to 1.6.1 in the all group
  • Bump chainguard-dev/actions from 1.5.16 to 1.6.0 in the all group
  • Bump chainguard-dev/actions from 1.5.14 to 1.5.16 in the all group
  • Bump chainguard-dev/actions from 1.5.13 to 1.5.14 in the all group
  • Bump github.com/sigstore/rekor from 1.4.3 to 1.5.0
  • Bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to 2.4.1
  • Bump actions/setup-go from 6.1.0 to 6.2.0 in the all group
  • Bump github.com/sigstore/fulcio from 1.8.4 to 1.8.5
  • Bump github.com/sigstore/cosign/v2 from 2.6.1 to 2.6.2 in the all group
  • Bump chainguard-dev/actions from 1.5.10 to 1.5.11 in the all group
  • Bump github.com/sigstore/fulcio from 1.7.1 to 1.8.3
  • Bump github.com/sigstore/sigstore
  • Bump actions/upload-artifact from 5.0.0 to 6.0.0
  • bump golangci-lint
  • update gorelease sing to works with cosign 3.0+
  • Bump github.com/spf13/cobra from 1.10.1 to 1.10.2 in the all group
  • Bump golangci/golangci-lint-action from 9.1.0 to 9.2.0 in the all group
  • Bump actions/checkout from 6.0.0 to 6.0.1 in the all group
  • Bump softprops/action-gh-release from 2.4.2 to 2.5.0 in the all group
  • Bump chainguard-dev/actions from 1.5.9 to 1.5.10 in the all group
  • Bump golangci/golangci-lint-action from 8.0.0 to 9.1.0
  • Bump actions/checkout from 5.0.1 to 6.0.0
  • Bump actions/setup-go from 6.0.0 to 6.1.0 in the all group
  • Bump golang.org/x/crypto from 0.43.0 to 0.45.0
  • Bump github.com/sigstore/rekor from 1.4.2 to 1.4.3 in the all group
  • Bump actions/upload-artifact from 4.6.2 to 5.0.0
  • Bump chainguard-dev/actions from 1.5.6 to 1.5.7 in the all group
  • Bump sigstore/cosign-installer from 3.10.0 to 4.0.0
  • Bump chainguard-dev/actions from 1.5.4 to 1.5.6 in the all group
  • Bump softprops/action-gh-release from 2.3.4 to 2.4.0 in the all group
  • Bump github.com/sigstore/cosign/v2 from 2.6.0 to 2.6.1 in the all group
  • Update to version 0.4.1:
  • Reverse platform+os naming scheme
  • Update to version 0.4.0:
  • update go, goreleaser and update/clean ci
  • Bump sigs.k8s.io/release-utils from 0.12.1 to 0.12.2 in the all group
  • Packaging improvements:
  • Update to BuildRequires: golang(API) >= 1.25 matching go.mod
  • Update to version 0.3.0+git181.33bac59:
  • Bump sigstore/cosign-installer from 3.9.2 to 3.10.0 in the all group
  • Fix break w/cosign 2.6.0
  • Bump cosign & go-vex
  • Fix 2.4 linter nits
  • Bump softprops/action-gh-release from 2.3.2 to 2.3.3 in the all group
  • Bump github.com/spf13/cobra from 1.9.1 to 1.10.1
  • Bump actions/setup-go from 5.5.0 to 6.0.0
  • Bump github.com/stretchr/testify from 1.11.0 to 1.11.1 in the all group
  • Bump github.com/stretchr/testify from 1.10.0 to 1.11.0
  • Bump github.com/go-viper/mapstructure/v2 in the go_modules group
  • Bump goreleaser/goreleaser-action from 6.3.0 to 6.4.0 in the all group
  • update release-utils and fix pkg name
  • Bump actions/checkout from 4.2.2 to 5.0.0
  • Bump github.com/secure-systems-lab/go-securesystemslib in the all group
  • Bump github.com/sigstore/rekor from 1.3.10 to 1.4.0
  • Bump sigs.k8s.io/release-utils from 0.11.1 to 0.12.0
  • Bump sigstore/cosign-installer from 3.9.1 to 3.9.2 in the all group
  • Bump github.com/sigstore/cosign/v2 from 2.5.2 to 2.5.3 in the all group
  • Bump sigstore/cosign-installer from 3.9.0 to 3.9.1 in the all group
  • Bump github.com/sigstore/cosign/v2 from 2.5.1 to 2.5.2 in the all group
  • Bump sigstore/cosign-installer from 3.8.2 to 3.9.0 in the all group
  • migrate config to v2
  • Bump golangci/golangci-lint-action from 6.5.2 to 8.0.0
  • Update to version 0.3.0+git133.ff97560:
  • Bump softprops/action-gh-release from 2.3.0 to 2.3.2 in the all group
  • Bump github.com/cloudflare/circl in the go_modules group
  • Bump softprops/action-gh-release from 2.2.2 to 2.3.0 in the all group
  • Bump actions/setup-go from 5.4.0 to 5.5.0 in the all group
  • Bump github.com/sigstore/sigstore from 1.9.3 to 1.9.4 in the all group
  • Bump sigstore/cosign-installer from 3.8.1 to 3.8.2 in the all group
  • Bump softprops/action-gh-release from 2.2.1 to 2.2.2 in the all group
  • Bump ko-build/setup-ko from 0.8 to 0.9 in the all group
  • Bump github.com/sigstore/cosign/v2 from 2.4.3 to 2.5.0
  • Bump goreleaser/goreleaser-action from 6.2.1 to 6.3.0 in the all group
  • Bump sigs.k8s.io/release-utils from 0.11.0 to 0.11.1 in the all group
  • Bump github.com/golang-jwt/jwt/v4 in the go_modules group
  • Bump golangci/golangci-lint-action from 6.5.1 to 6.5.2 in the all group
  • Bump github.com/sigstore/sigstore from 1.8.15 to 1.9.1
  • Bump golang.org/x/net from 0.35.0 to 0.36.0 in the go_modules group
  • Bump golangci/golangci-lint-action from 6.5.0 to 6.5.1 in the all group
  • Bump github.com/go-jose/go-jose/v3 in the go_modules group
  • Bump github.com/go-jose/go-jose/v4 in the go_modules group
  • Bump actions/upload-artifact from 4.6.0 to 4.6.1 in the all group
  • Bump sigstore/cosign-installer from 3.8.0 to 3.8.1 in the all group
  • use go1.24 and update golangci-lint
  • Bump golangci/golangci-lint-action from 6.3.3 to 6.5.0 in the all group
  • Bump github.com/spf13/cobra from 1.8.1 to 1.9.1
  • Bump github.com/sigstore/sigstore from 1.8.12 to 1.8.14 in the all group
  • Bump golangci/golangci-lint-action from 6.3.2 to 6.3.3 in the all group
  • Bump goreleaser/goreleaser-action from 6.1.0 to 6.2.1 in the all group
  • Bump golangci/golangci-lint-action from 6.3.0 to 6.3.2 in the all group
  • Bump sigstore/cosign-installer from 3.7.0 to 3.8.0 in the all group
  • Bump golangci/golangci-lint-action from 6.2.0 to 6.3.0 in the all group
  • Bump sigs.k8s.io/release-utils from 0.9.0 to 0.10.0
  • Bump github.com/sigstore/rekor from 1.3.8 to 1.3.9 in the all group
  • Bump actions/setup-go from 5.2.0 to 5.3.0 in the all group
  • Bump golangci/golangci-lint-action from 6.1.1 to 6.2.0 in the all group
  • Bump sigs.k8s.io/release-utils from 0.8.5 to 0.9.0
  • Bump go dependencies manually
  • Bump ko-build/setup-ko from 0.7 to 0.8 in the all group
  • Bump actions/upload-artifact from 4.5.0 to 4.6.0 in the all group
  • Bump softprops/action-gh-release from 2.2.0 to 2.2.1 in the all group
  • Bump actions/upload-artifact from 4.4.3 to 4.5.0 in the all group
  • Bump golang.org/x/crypto from 0.28.0 to 0.31.0 in the go_modules group
  • Bump softprops/action-gh-release from 2.0.9 to 2.1.0 in the all group
  • Bump goreleaser/goreleaser-action from 6.0.0 to 6.1.0 in the all group
  • Bump softprops/action-gh-release from 2.0.8 to 2.0.9 in the all group
  • Update verify.yaml
  • Update release.yaml
  • Update ci-build-test.yaml
  • Bump actions/setup-go from 5.0.2 to 5.1.0 in the all group
  • Bump actions/checkout from 4.2.1 to 4.2.2 in the all group
  • Bump github.com/sigstore/sigstore from 1.8.9 to 1.8.10 in the all group
  • Bump actions/upload-artifact from 4.4.2 to 4.4.3 in the all group
  • Bump actions/upload-artifact from 4.4.1 to 4.4.2 in the all group
  • Bump sigstore/cosign-installer from 3.6.0 to 3.7.0 in the all group
  • Bump golangci/golangci-lint-action from 6.1.0 to 6.1.1 in the all group
  • Bump github.com/sigstore/cosign/v2 from 2.4.0 to 2.4.1 in the all group
  • Bump actions/checkout from 4.1.7 to 4.2.0 in the all group
  • Bump sigs.k8s.io/release-utils from 0.8.4 to 0.8.5 in the all group
  • upgrade to go1.23
References

Affected packages

openSUSE:Leap 16.0 / vexctl

Package

Name
vexctl
Purl
pkg:rpm/opensuse/vexctl&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.4+git20.5d61136-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "vexctl": "0.4.4+git20.5d61136-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21481-1.json"