{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20584-1","published":"2026-04-16T12:46:59Z","modified":"2026-04-22T18:27:19.392367Z","related":["CVE-2026-33186"],"upstream":["CVE-2026-33186"],"summary":"Security update for v2ray-core","details":"This update for v2ray-core fixes the following issues:\n\nChanges in v2ray-core:\n\n- Update version to 5.47.0\n  * Add sticky choice option for leastping\n  * Add support for enrollment links in tlsmirror\n  * Add Wireguard Outbound (unreleased)\n  * Add sticky choice option for leastping\n  * Generalize IP address parsing in TUN stack options\n  * Fix bugs\n\n- CVE-2026-33186: google.golang.org/grpc: Fixed authorization bypass caused by\n  improper validation of the HTTP/2 :path pseudo-header (boo#1260329)\n\n- Update version to 5.44.1\n  * uTLS: bundled library updated to v1.8.2 for Chrome120 imitation profile\n    identification\n  * Update golang toolchain to v1.25.6, which fixed an vulnerable\n    (tls.Config).Clone function\n  * Fix bugs\n\n- Update version to 5.42.0\n  * Add TLSMirror bootstrap enrollment and self enrollment feature\n  * TLSMirror Inverse Role Request Tripper Enrollment Server Support\n","affected":[{"package":{"name":"v2ray-core","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/v2ray-core&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.47.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"golang-github-v2fly-v2ray-core":"5.47.0-bp160.1.1","v2ray-core":"5.47.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20584-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260329"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33186"}]}