openSUSE-SU-2026:21801-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21801-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21801-1
Upstream
CVE (10)
Related
Published
2026-09-07T15:03:57Z
Modified
2026-09-10T18:23:47Z
Summary
Security update for trivy
Details

This update for trivy fixes the following issues:

  • CVE-2026-24122: github.com/sigstore/cosign/v2/pkg/cosign: improper validation of certificates that outlive expired CA certificates (bsc#1258543).
  • CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST request through the X-HTTP-Method-Override header and bypass established access control (bsc#1278002).
  • CVE-2026-41178: go.opentelemetry.io/otel/baggage, go.opentelemetry.io/otel/propagation: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276745).
  • CVE-2026-50163: oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks (bsc#1278702).
  • CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278624).
  • CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279390).
  • CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279395).
  • CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing :authority and Host headers in gRPC-Go xDS servers (bsc#1279392).
References

Affected packages

openSUSE:Leap 16.0 / trivy

Package

Name
trivy
Purl
pkg:rpm/opensuse/trivy&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.74.0-160000.2.1

Ecosystem specific

{
    "binaries":  [
        {
            "trivy":  "0.74.0-160000.2.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21801-1.json"