{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20788-1","published":"2026-05-22T11:50:52Z","modified":"2026-05-26T18:24:15.174834861Z","related":["CVE-2025-30153","CVE-2025-47913","CVE-2025-47914","CVE-2025-58181","CVE-2026-32285","CVE-2026-33186"],"upstream":["CVE-2025-30153","CVE-2025-47913","CVE-2025-47914","CVE-2025-58181","CVE-2026-32285","CVE-2026-33186"],"summary":"Security update for mcphost","details":"This update for mcphost fixes the following issues\n\n- CVE-2025-30153: github.com/getkin/kin-openapi/openapi3filter: Improper Handling of Highly Compressed Data (Data\n  Amplification) in github.com/getkin/kin-openapi/openapi3filter (bsc#1264762).\n- CVE-2025-47913: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in\n  response to a key listing or (bsc#1265274).\n- CVE-2025-47914: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds\n  read (bsc#1265275).\n- CVE-2025-58181: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption\n  (bsc#1253952).\n- CVE-2026-32285: github.com/buger/jsonparser: denial of service via malformed JSON input (bsc#1264759).\n- CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo-\n  header (bsc#1260224).\n\nChanges for mcphost:\n\n- Updated to version 0.34.0\n * Features:\n - Upgrade charmbracelet libs to v2 (bubbletea, lipgloss, bubbles)\n - Add Google Vertex AI support for Claude models\n - Add new models.\n * Fixes:\n - Eliminate escape sequence leak from spinner tea.Program instances.\n - Fix anthropic api issue.\n - Convert JSON Schema draft-07 exclusive bounds to draft-04 format.\n * Upgrade all dependencies to latest versions, resolve security issues\n and to obtain Go 1.26 compatibility.\n","references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253952"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260224"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264759"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264762"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265274"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265275"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-30153"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-47913"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-47914"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58181"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32285"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33186"}]}