{"id":"openSUSE-SU-2026:21899-1","summary":"Security update for alloy","details":"This update for alloy fixes the following issues:\n\n- CVE-2026-1229: github.com/cloudflare/circl: the CombinedMult function in the ecc/p384 package produces an incorrect\n  value for specific inputs (bsc#1265542).\n- CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE\n  (bsc#1265845).\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation\n  bypass and privilege escalation (bsc#1266654).\n- CVE-2026-41506: github.com/go-git/go-git/v5: HTTP authentication credential leak when following redirects during\n  smart-HTTP clone and fetch operations (bsc#1264949).\n- CVE-2026-41606: github.com/apache/thrift: crafted nested messages in c_glib dispatch can lead to uncontrolled\n  recursion and denial of service (bsc#1263324).\n- CVE-2026-41607: github.com/apache/thrift: crafted message with improper length validation can lead to an out-of-bounds\n  read and potential information disclosure (bsc#1263289).\n\nChanges for alloy:\n\n- Update to version 1.18.0:\n * BREAKING: otelcol HTTP receivers default to idle_timeout=\"1m\",\n read_header_timeout=\"1m\", write_timeout=\"30s\" to match\n upstream. Affects otlp, faro, jaeger, zipkin, influxdb,\n splunkhec, datadog and jaeger_remote_sampling.\n * Back off usage reporting on persistent failure\n * Fix Beyla glob parsing\n * Bump github.com/prometheus/procfs for XFS Collector fix\n * database_observability.mysql: Simplify denylist in-memory map\n * database_observability.postgres: Handle DSN with unix sockets\n * database_observability.postgres: Update collect intervals\n * database_observability: Explain-plan conditions now redact\n * Don't emit error log when remotecfg is unused\n * For a full list of changes, please refer to the CHANGELOG:\n https://github.com/grafana/alloy/blob/v1.18.0/CHANGELOG.md\n","modified":"2026-09-25T18:23:15.595620486Z","published":"2026-09-21T12:26:04Z","related":["CVE-2026-10722","CVE-2026-1229","CVE-2026-33814","CVE-2026-39821","CVE-2026-41506","CVE-2026-41606","CVE-2026-41607"],"upstream":["CVE-2026-10722","CVE-2026-1229","CVE-2026-33814","CVE-2026-39821","CVE-2026-41506","CVE-2026-41606","CVE-2026-41607"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263289"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263324"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264949"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265542"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265845"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266654"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-10722"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1229"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33814"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41506"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41606"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41607"}],"affected":[{"package":{"name":"alloy","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/alloy&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.18.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"alloy":"1.18.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21899-1.json"}}],"schema_version":"1.9.0"}