{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20921-1","published":"2026-06-08T14:12:20Z","modified":"2026-06-10T18:24:16.930286779Z","related":["CVE-2026-33186"],"upstream":["CVE-2026-33186"],"summary":"Security update for elemental-toolkit","details":"This update for elemental-toolkit fixes the following issue\n\n- CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo-\n  header (bsc#1260277).\n\nChanges:\n\n- Update to v2.3.4:\n * 974af043 Bump golang.org/x/net to v0.55.0 (bsc#1267168 bsc#1251679)\n * ae39c90f Bump golang.org/x/crypto to v0.52.0 (bsc#1266187)\n- Update to v2.3.3:\n * 8b4af274 Avoid pulling binaries with curl\n * d46e30f4 Bump golangci/golangci-lint-action to v9\n * 02caf200 Bump github.com/spf13/cobra library\n * e29e1fbf Bump github.com/jaypipes/ghw library\n * 652654e1 Bump github.com/bramvdbogaerde/go-scp library\n * f94a0c58 Bump google.golang.org/grpc library (bsc#1260277 CVE-2026-33186)\n * dc1a2056 Bump github.com/ulikunitz/xz library\n * 337a986c Update headers to 2026\n * d6aac085 Switch from TW to Leap 16.0 for green flavor\n","affected":[{"package":{"name":"elemental-toolkit","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/elemental-toolkit&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.4-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"elemental-toolkit":"2.3.4-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20921-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1251679"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260277"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266187"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267168"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33186"}]}