{"schema_version":"1.7.5","id":"SUSE-SU-2026:2285-1","published":"2026-06-05T12:16:31Z","modified":"2026-06-06T07:30:26.543118377Z","related":["CVE-2026-25680","CVE-2026-25681","CVE-2026-27136","CVE-2026-39821","CVE-2026-42502","CVE-2026-42506"],"upstream":["CVE-2026-25680","CVE-2026-25681","CVE-2026-27136","CVE-2026-39821","CVE-2026-42502","CVE-2026-42506"],"summary":"Security update for yq","details":"This update for yq fixes the following issues:\n\n- CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html: multiple issues\n  when parsing HTML files (bsc#1267053).\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation\n  bypass and privilege escalation (bsc#1267199).\n","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262285-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267053"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267199"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25680"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27136"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42502"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42506"}]}