{"id":"SUSE-SU-2026:2096-1","summary":"Security update for yq","details":"This update for yq fixes the following issues\n\n- CVE-2025-22872: golang.org/x/net/html: incorrectly interpreted tags can cause content to be placed wrong scope during\n  DOM construction (bsc#1241719).\n- CVE-2025-47911: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents\n  (bsc#1251339).\n- CVE-2025-58190: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially\n  crafted input (bsc#1251540).\n- CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE\n  (bsc#1266248).\n\nChanges for yq:\n\n- update to v4.53.2\n","modified":"2026-05-28T08:15:06.740955487Z","published":"2026-05-27T14:20:25Z","related":["CVE-2025-22872","CVE-2025-47911","CVE-2025-58190","CVE-2026-33814"],"upstream":["CVE-2025-22872","CVE-2025-47911","CVE-2025-58190","CVE-2026-33814"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262096-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241719"},{"type":"REPORT","url":"https://bugzilla.suse.com/1251339"},{"type":"REPORT","url":"https://bugzilla.suse.com/1251540"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266248"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22872"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-47911"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58190"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33814"}],"schema_version":"1.7.5"}