{"schema_version":"1.7.5","id":"openSUSE-SU-2026:21277-1","published":"2026-07-08T16:27:05Z","modified":"2026-07-11T18:24:35.800330774Z","related":["CVE-2026-1229","CVE-2026-39821"],"upstream":["CVE-2026-1229","CVE-2026-39821"],"summary":"Security update for go-sendxmpp","details":"This update for go-sendxmpp fixes the following issues:\n\nChanges in go-sendxmpp:\n\n- Update to 0.16.0:\n  Added:\n  * Add Ox support to http-upload.\n  * Add Ox support for private group chats.\n  * Show error cause if joining MUCs failedi (requires go-xmpp >= v0.3.5).\n  Changed:\n  * Fix --ox-delete-nodes.\n  * Fix receiving of 1-1 messages while joined in a MUC.\n  * Use go-sendxmpp + a random ID as fallback MUC alias.\n  * Strip leading \"xmpp:\" from recipients.\n  * Strip trailing \"?join\" from MUC JIDs.\n  * Add context for timeouts in stanza handling.\n  * Check ID for disco items reply (requires go-xmpp >= v0.3.6).\n  * Reduce channel buffer size to 1 where only one item will be returned.\n  * Deprecate legacy PGP.\n  * CVE-2026-1229: The CombinedMult function produces an incorrect value (bsc#1265538)\n    Bump circl to 1.6.3\n  * CVE-2026-39821: Failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266617)\n    Bump net to 0.56.0\n\n- Update to 0.15.8:\n  * Fix windows build (windows doesn't support syscalls Setgid and Setuid).\n\n- Update to 0.15.7:\n  * Fix http-upload with legacy PGP encryption.\n  * Fix reading of environment variables.\n  * Fix a bug in looking up host meta 2.\n  * Try to drop root privileges before connecting to the server.\n  * Fix crash if a config key has no value.\n  * Use a salt for stored FAST token.\n  * Increase scrypt iterations for storing FAST token from 32768 to 65536.\n  * Log a warning when --no-tls-verify or -n is set.\n\n- Update to 0.15.6:\n  Added:\n  * New config option allow_plain.\n  Changed:\n  * Explain each configuration option in manpage go-sendxmpp(5).\n  * Improve config parsing robustness.\n  * Update link in manpage as Gitlab calls issues now work items.\n  * Recognize stanza size limit updates after authentication (via go-xmpp >= v0.3.3).\n  * Tell connection target in error message when failing to connect.\n- Drop tar-scm service and use regular tarball and go_modules\n\n- Update to 0.15.5:\n  * Fix SASL SCRAM Downgrade Protection in case of server providing\n    different mechanisms for SASL and SASL2 (requires go-xmpp >0 v0.3.2).\n\n- Update to 0.15.4:\n  * http-upload: Manually set content length for HTTP request (fixes\n    issues with certain http modules/proxies).\n\n- Update to 0.15.3:\n  * Fix PLAIN authentication for SASL2 (requires go-xmpp >= v0.3.1).\n\n- Update to 0.15.2:\n  * Use UUIDv7 instead of UUIDv4 for stanza IDs (requires go-xmpp >= v0.2.19).\n  * Fix stanza syntax error for legacy PGP messages.\n  * Print error if legacy PGP and Ox are requested simultaneously.\n  * Reworked OOB file sending and http-upload to use new functions\n    from go-xmpp library (requires go-xmpp >= v0.3.0).\n  * Try password login if FAST login fails.\n","affected":[{"package":{"name":"go-sendxmpp","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/go-sendxmpp&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.16.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"go-sendxmpp":"0.16.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21277-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265538"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266617"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1229"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"}]}