{"id":"openSUSE-SU-2026:21653-1","summary":"Security update for v2ray-core","details":"This update for v2ray-core fixes the following issues:\n\nChanges in v2ray-core:\n\n- Update version to 5.53.0\n  * Add X-Forwarded-For support to gRPC transport\n  * Add Stream based Packet Addr for UDP Connections\n  * rrpit: compact session, async send, session recovery\n  * Add socks5ify engineering command\n  * Fix bugs\n  * Update modules (boo#1276119 and CVE-2026-72817, CVE-2026-72815, CVE-2026-72816)\n\n- Update version to 5.51.2\n  * Wireguard Add TCP Listener support for wireguard outbound\n  * Stun Nat Type Testing\n  * Better server failure detection and PreserveSourceIPPortWhenDestNATMapping\n    detection\n  * Improve API instance support\n  * feat: grpc: allow configurable keepalive and initial windows size\n  * Add RRPIT - Rapid Reliable Packet Interactive Transport\n  * Add WebRTC Tunnel Support in V2Ray(unreleased)\n  * also parse X-Forwarded-For in httpupgrade\n  * gdocsviewer: Add Google Docs Viewer based transport\n  * gdocsviewer: Refine poll logic and allow custom headers to reduce rate limiting\n  * gdocsviewer: allow adding headers in public config\n  * Fix bugs (boo#1258546 and CVE-2026-27017)\n\n- update golang.org/x/net to 0.55.0 to fix boo#1266787 and CVE-2026-39821\n","modified":"2026-08-27T18:23:31.796226004Z","published":"2026-08-25T18:20:49Z","related":["CVE-2026-27017","CVE-2026-39821","CVE-2026-72815","CVE-2026-72816","CVE-2026-72817"],"upstream":["CVE-2026-27017","CVE-2026-39821","CVE-2026-72815","CVE-2026-72816","CVE-2026-72817"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258546"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266787"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276119"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27017"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-72815"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-72816"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-72817"}],"affected":[{"package":{"name":"v2ray-core","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/v2ray-core&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.53.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"golang-github-v2fly-v2ray-core":"5.53.0-bp160.1.1","v2ray-core":"5.53.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21653-1.json"}}],"schema_version":"1.9.0"}