{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20770-1","published":"2026-05-19T14:15:05Z","modified":"2026-05-22T18:23:49.770428904Z","related":["CVE-2026-1229","CVE-2026-41506"],"upstream":["CVE-2026-1229","CVE-2026-41506"],"summary":"Security update for git-bug","details":"This update for git-bug fixes the following issues:\n\nChanges in git-bug:\n\n- CVE-2026-1229: CIRCL had an incorrect calculation in\n  secp384r1 CombinedMult (bsc#1265416, GO-2026-4550):\n  updated github.com/cloudflare/circl to v1.6.3\n- CVE-2026-41506: HTTP authentication credential leak when\n  following redirects during smart-HTTP clone and fetch\n  operations (bsc#1264955, GO-2026-4910):\n  updated github.com/go-git/go-git/v5 to v5.17.1\n","references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264955"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265416"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1229"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41506"}]}