{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20809-1","published":"2026-05-17T21:24:43Z","modified":"2026-05-29T18:24:10.270635001Z","related":["CVE-2025-64702","CVE-2025-69725","CVE-2026-25934","CVE-2026-33186","CVE-2026-33747","CVE-2026-33748","CVE-2026-34986","CVE-2026-39984","CVE-2026-41506"],"upstream":["CVE-2025-64702","CVE-2025-69725","CVE-2026-25934","CVE-2026-33186","CVE-2026-33747","CVE-2026-33748","CVE-2026-34986","CVE-2026-39984","CVE-2026-41506"],"summary":"Security update for trivy","details":"This update for trivy fixes the following issues\n\n- CVE-2025-64702: github.com/quic-go/quic-go/http3: quic-go HTTP/3 QPACK Header Expansion DoS (bsc#1255366).\n- CVE-2025-69725: github.com/go-chi/chi/v5: incorrect input validation in the RedirectSlashes function can lead to an\n  open redirect (bsc#1258513).\n- CVE-2026-25934: github.com/go-git/go-git/v5: improper verification of data integrity values for .pack and .idx files\n  can lead to the consumption of corrupted files (bsc#1258094).\n- CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo-\n  header (bsc#1260193).\n- CVE-2026-33747: github.com/moby/buildkit: malicious frontends can craft API messages that cause files to be written\n  outside of the BuildKit state directory (bsc#1260971).\n- CVE-2026-33748: github.com/moby/buildkit: insufficient validation of Git URL fragment subdir components may allow\n  access to files outside the checked-out Git repository (bsc#1261052).\n- CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of\n  service (bsc#1262893).\n- CVE-2026-39984: github.com/sigstore/timestamp-authority/v2/pkg/verification: improper certificate validation can be\n  used to bypass some authorization controls (bsc#1262389).\n- CVE-2026-41506: github.com/go-git/go-git/v5: HTTP authentication credential leak when following redirects during\n  smart-HTTP clone and fetch operations (bsc#1264873).\n\nChanges for trivy:\n\n- Updated go-git to 5.18.0.\n- Updated to version 0.70.0.\n","references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255366"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258094"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258513"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260193"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260971"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261052"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262389"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262893"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264873"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-64702"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-69725"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25934"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33747"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33748"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39984"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41506"}]}