{"id":"openSUSE-SU-2026:21662-1","summary":"Security update for glab","details":"This update for glab fixes the following issues:\n\nChanges in glab:\n\n- Update to version 1.114.0:\n  * feat(api): support dynamic custom headers for authenticating proxies\n  * feat(artifact-registry): add glab artifact-registry login --docker\n  * feat(artifact-registry): resolve artifact registries in the Docker\n    credential helper\n  * feat(mr): show source and target branches in view\n  * feat(update): detect more install methods for the upgrade nudge\n  * fix(cmdutils): resolve same-host SSH remotes to the right account\n  * fix(config): resolve YAML alias nodes in hosts config\n  * fix(git): detect \"no git repository\" by exit status, not message text\n  * fix: glab can not set group level variable masked or masked and hidden\n\n- CVE-2026-39821: reject all-ASCII xn-- Punycode labels in the vendored\n  golang.org/x/net/idna package regardless of Go's unicode.Version (boo#1266614).\n","modified":"2026-08-27T18:23:30.386474491Z","published":"2026-08-26T16:07:54Z","related":["CVE-2024-45338","CVE-2024-6104","CVE-2025-22872","CVE-2025-47911","CVE-2025-58190","CVE-2026-25681","CVE-2026-27136","CVE-2026-33814","CVE-2026-39821","CVE-2026-39827","CVE-2026-39828","CVE-2026-39829","CVE-2026-39830","CVE-2026-39831","CVE-2026-39832","CVE-2026-39833","CVE-2026-39834","CVE-2026-39835","CVE-2026-42502","CVE-2026-42506","CVE-2026-42508","CVE-2026-46595","CVE-2026-46597","CVE-2026-46598"],"upstream":["CVE-2024-45338","CVE-2024-6104","CVE-2025-22872","CVE-2025-47911","CVE-2025-58190","CVE-2026-25681","CVE-2026-27136","CVE-2026-33814","CVE-2026-39821","CVE-2026-39827","CVE-2026-39828","CVE-2026-39829","CVE-2026-39830","CVE-2026-39831","CVE-2026-39832","CVE-2026-39833","CVE-2026-39834","CVE-2026-39835","CVE-2026-42502","CVE-2026-42506","CVE-2026-42508","CVE-2026-46595","CVE-2026-46597","CVE-2026-46598"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1227037"},{"type":"REPORT","url":"https://bugzilla.suse.com/1235353"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241815"},{"type":"REPORT","url":"https://bugzilla.suse.com/1251467"},{"type":"REPORT","url":"https://bugzilla.suse.com/1251685"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265775"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265832"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266172"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266614"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267155"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45338"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6104"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22872"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-47911"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58190"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27136"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33814"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39827"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39828"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39829"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39830"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39831"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39832"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39833"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39834"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39835"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42502"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42506"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42508"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46595"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46597"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46598"}],"affected":[{"package":{"name":"glab","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/glab&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.114.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"glab-bash-completion":"1.114.0-bp160.1.1","glab-doc":"1.114.0-bp160.1.1","glab-fish-completion":"1.114.0-bp160.1.1","glab-zsh-completion":"1.114.0-bp160.1.1","glab":"1.114.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21662-1.json"}}],"schema_version":"1.9.0"}