{"schema_version":"1.7.5","id":"openSUSE-SU-2026:21481-1","published":"2026-07-30T04:41:29Z","modified":"2026-07-31T18:24:08.134854039Z","related":["CVE-2024-45337","CVE-2025-22868","CVE-2025-22869","CVE-2025-22870","CVE-2025-27144","CVE-2025-30204","CVE-2025-58181","CVE-2026-22772","CVE-2026-24137"],"upstream":["CVE-2024-45337","CVE-2025-22868","CVE-2025-22869","CVE-2025-22870","CVE-2025-27144","CVE-2025-30204","CVE-2025-58181","CVE-2026-22772","CVE-2026-24137"],"summary":"Security update for vexctl","details":"This update for vexctl fixes the following issues:\n\n- CVE-2024-45337: golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in\n  golang.org/x/crypto (bsc#1234486).\n- CVE-2025-22868: golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2\n  (bsc#1239186).\n- CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh\n  (bsc#1239323).\n- CVE-2025-22870: golang.org/x/net/proxy: proxy bypass using IPv6 zone IDs (bsc#1238683).\n- CVE-2025-27144: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: Go JOSE's Parsing Vulnerable to Denial of\n  Service (bsc#1237611).\n- CVE-2025-30204: github.com/golang-jwt/jwt/v4: jwt-go allows excessive memory allocation during header parsing\n  (bsc#1240444).\n- CVE-2025-58181: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption\n  (bsc#1253802).\n- CVE-2026-22772: github.com/sigstore/fulcio: bypass MetaIssuer URL validation bypass can trigger SSRF to arbitrary\n  internal services (bsc#1256535).\n- CVE-2026-24137: github.com/sigstore/sigstore/pkg/tuf: legacy TUF client allows for arbitrary file writes with target\n  cache path traversal (bsc#1257138).\n\nChanges for vexctl:\n\n- Update to version 0.4.4+git20.5d61136:\n\n * build(deps): Bump github.com/sigstore/cosign/v2\n * build(deps): Bump actions/setup-go from 6.5.0 to 7.0.0\n * build(deps): Bump the all group across 1 directory with 5 updates\n * build(deps): Bump github.com/sigstore/rekor in the all group\n * build(deps): Bump the all group with 4 updates\n * build(deps): Bump github.com/google/go-containerregistry\n * build(deps): Bump actions/setup-go from 6.4.0 to 6.5.0 in the all group\n * build(deps): Bump the all group across 1 directory with 2 updates\n * build(deps): Bump actions/checkout from 6.0.3 to 7.0.0\n * build(deps): Bump chainguard-dev/actions in the all group\n\n- Update to version 0.4.4:\n\n * fix signature duplication\n * fix lints\n * housekeeping - deps update and ci cleanup\n * build(deps): Bump the all group with 2 updates\n * build(deps): Bump github.com/sigstore/sigstore in the all group\n * build(deps): Bump golangci/golangci-lint-action in the all group\n\n- Update to version 0.4.1+git147.b7e6ef0:\n\n * build(deps): Bump goreleaser/goreleaser-action in the all group\n * Bump sigstore/cosign-installer from 4.1.1 to 4.1.2 in the all group\n * Bump chainguard-dev/actions from 1.6.17 to 1.6.19 in the all group\n * Bump chainguard-dev/actions from 1.6.16 to 1.6.17 in the all group\n * Bump github.com/package-url/packageurl-go in the all group\n * Bump the all group with 2 updates\n\n- Update to version 0.4.1+git133.efecaf7:\n\n * Bump github.com/secure-systems-lab/go-securesystemslib\n\n- Update to version 0.4.1+git129.c7f3066:\n\n * Bump github.com/google/go-containerregistry in the all group\n * Bump github.com/sigstore/timestamp-authority/v2 from 2.0.3 to 2.0.6\n * Bump softprops/action-gh-release from 2.6.1 to 3.0.0\n * Bump chainguard-dev/actions from 1.6.13 to 1.6.14 in the all group\n * Bump actions/upload-artifact from 7.0.0 to 7.0.1 in the all group\n * Bump github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3 in the all group\n * Bump kubernetes-sigs/release-actions in the all group\n * Bump github.com/in-toto/in-toto-golang from 0.9.0 to 0.10.0\n * Bump the all group across 1 directory with 2 updates\n * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4\n * fix(add): allow add without --product flag\n * Use gomod version, bump linter\n * Port vexctl to intoto/attestation\n * Bump the all group across 1 directory with 5 updates\n * Bump google.golang.org/grpc from 1.78.0 to 1.79.3\n\n- Update to version 0.4.1+git96.558125d:\n\n * Bump the all group across 1 directory with 3 updates\n * Bump chainguard-dev/actions from 1.6.5 to 1.6.6 in the all group\n * Bump github.com/google/go-containerregistry from 0.20.7 to 0.21.0\n * Bump actions/upload-artifact from 6.0.0 to 7.0.0\n * Bump goreleaser/goreleaser-action from 6.4.0 to 7.0.0\n * Bump chainguard-dev/actions from 1.6.2 to 1.6.4 in the all group\n\n- Update to version 0.4.1+git78.f951e3a:\n\n * Bump chainguard-dev/actions from 1.6.1 to 1.6.2 in the all group\n\n- Update to version 0.4.1+git76.10d7a2e:\n\n * Bump chainguard-dev/actions from 1.6.0 to 1.6.1 in the all group\n * Bump chainguard-dev/actions from 1.5.16 to 1.6.0 in the all group\n * Bump chainguard-dev/actions from 1.5.14 to 1.5.16 in the all group\n * Bump chainguard-dev/actions from 1.5.13 to 1.5.14 in the all group\n * Bump github.com/sigstore/rekor from 1.4.3 to 1.5.0\n * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to 2.4.1\n * Bump actions/setup-go from 6.1.0 to 6.2.0 in the all group\n * Bump github.com/sigstore/fulcio from 1.8.4 to 1.8.5\n * Bump github.com/sigstore/cosign/v2 from 2.6.1 to 2.6.2 in the all group\n * Bump chainguard-dev/actions from 1.5.10 to 1.5.11 in the all group\n * Bump github.com/sigstore/fulcio from 1.7.1 to 1.8.3\n * Bump github.com/sigstore/sigstore\n * Bump actions/upload-artifact from 5.0.0 to 6.0.0\n * bump golangci-lint\n * update gorelease sing to works with cosign 3.0+\n * Bump github.com/spf13/cobra from 1.10.1 to 1.10.2 in the all group\n * Bump golangci/golangci-lint-action from 9.1.0 to 9.2.0 in the all group\n * Bump actions/checkout from 6.0.0 to 6.0.1 in the all group\n * Bump softprops/action-gh-release from 2.4.2 to 2.5.0 in the all group\n * Bump chainguard-dev/actions from 1.5.9 to 1.5.10 in the all group\n * Bump golangci/golangci-lint-action from 8.0.0 to 9.1.0\n * Bump actions/checkout from 5.0.1 to 6.0.0\n * Bump actions/setup-go from 6.0.0 to 6.1.0 in the all group\n * Bump golang.org/x/crypto from 0.43.0 to 0.45.0\n * Bump github.com/sigstore/rekor from 1.4.2 to 1.4.3 in the all group\n * Bump actions/upload-artifact from 4.6.2 to 5.0.0\n * Bump chainguard-dev/actions from 1.5.6 to 1.5.7 in the all group\n * Bump sigstore/cosign-installer from 3.10.0 to 4.0.0\n * Bump chainguard-dev/actions from 1.5.4 to 1.5.6 in the all group\n * Bump softprops/action-gh-release from 2.3.4 to 2.4.0 in the all group\n * Bump github.com/sigstore/cosign/v2 from 2.6.0 to 2.6.1 in the all group\n\n- Update to version 0.4.1:\n\n * Reverse platform+os naming scheme\n\n- Update to version 0.4.0:\n\n * update go, goreleaser and update/clean ci\n * Bump sigs.k8s.io/release-utils from 0.12.1 to 0.12.2 in the all group\n\n- Packaging improvements:\n\n * Update to BuildRequires: golang(API) >= 1.25 matching go.mod\n\n- Update to version 0.3.0+git181.33bac59:\n\n * Bump sigstore/cosign-installer from 3.9.2 to 3.10.0 in the all group\n * Fix break w/cosign 2.6.0\n * Bump cosign & go-vex\n * Fix 2.4 linter nits\n * Bump softprops/action-gh-release from 2.3.2 to 2.3.3 in the all group\n * Bump github.com/spf13/cobra from 1.9.1 to 1.10.1\n * Bump actions/setup-go from 5.5.0 to 6.0.0\n * Bump github.com/stretchr/testify from 1.11.0 to 1.11.1 in the all group\n * Bump github.com/stretchr/testify from 1.10.0 to 1.11.0\n * Bump github.com/go-viper/mapstructure/v2 in the go_modules group\n * Bump goreleaser/goreleaser-action from 6.3.0 to 6.4.0 in the all group\n * update release-utils and fix pkg name\n * Bump actions/checkout from 4.2.2 to 5.0.0\n * Bump github.com/secure-systems-lab/go-securesystemslib in the all group\n * Bump github.com/sigstore/rekor from 1.3.10 to 1.4.0\n * Bump sigs.k8s.io/release-utils from 0.11.1 to 0.12.0\n * Bump sigstore/cosign-installer from 3.9.1 to 3.9.2 in the all group\n * Bump github.com/sigstore/cosign/v2 from 2.5.2 to 2.5.3 in the all group\n * Bump sigstore/cosign-installer from 3.9.0 to 3.9.1 in the all group\n * Bump github.com/sigstore/cosign/v2 from 2.5.1 to 2.5.2 in the all group\n * Bump sigstore/cosign-installer from 3.8.2 to 3.9.0 in the all group\n * migrate config to v2\n * Bump golangci/golangci-lint-action from 6.5.2 to 8.0.0\n\n- Update to version 0.3.0+git133.ff97560:\n\n * Bump softprops/action-gh-release from 2.3.0 to 2.3.2 in the all group\n * Bump github.com/cloudflare/circl in the go_modules group\n * Bump softprops/action-gh-release from 2.2.2 to 2.3.0 in the all group\n * Bump actions/setup-go from 5.4.0 to 5.5.0 in the all group\n * Bump github.com/sigstore/sigstore from 1.9.3 to 1.9.4 in the all group\n * Bump sigstore/cosign-installer from 3.8.1 to 3.8.2 in the all group\n * Bump softprops/action-gh-release from 2.2.1 to 2.2.2 in the all group\n * Bump ko-build/setup-ko from 0.8 to 0.9 in the all group\n * Bump github.com/sigstore/cosign/v2 from 2.4.3 to 2.5.0\n * Bump goreleaser/goreleaser-action from 6.2.1 to 6.3.0 in the all group\n * Bump sigs.k8s.io/release-utils from 0.11.0 to 0.11.1 in the all group\n * Bump github.com/golang-jwt/jwt/v4 in the go_modules group\n * Bump golangci/golangci-lint-action from 6.5.1 to 6.5.2 in the all group\n * Bump github.com/sigstore/sigstore from 1.8.15 to 1.9.1\n * Bump golang.org/x/net from 0.35.0 to 0.36.0 in the go_modules group\n * Bump golangci/golangci-lint-action from 6.5.0 to 6.5.1 in the all group\n * Bump github.com/go-jose/go-jose/v3 in the go_modules group\n * Bump github.com/go-jose/go-jose/v4 in the go_modules group\n * Bump actions/upload-artifact from 4.6.0 to 4.6.1 in the all group\n * Bump sigstore/cosign-installer from 3.8.0 to 3.8.1 in the all group\n * use go1.24 and update golangci-lint\n * Bump golangci/golangci-lint-action from 6.3.3 to 6.5.0 in the all group\n * Bump github.com/spf13/cobra from 1.8.1 to 1.9.1\n * Bump github.com/sigstore/sigstore from 1.8.12 to 1.8.14 in the all group\n * Bump golangci/golangci-lint-action from 6.3.2 to 6.3.3 in the all group\n * Bump goreleaser/goreleaser-action from 6.1.0 to 6.2.1 in the all group\n * Bump golangci/golangci-lint-action from 6.3.0 to 6.3.2 in the all group\n * Bump sigstore/cosign-installer from 3.7.0 to 3.8.0 in the all group\n * Bump golangci/golangci-lint-action from 6.2.0 to 6.3.0 in the all group\n * Bump sigs.k8s.io/release-utils from 0.9.0 to 0.10.0\n * Bump github.com/sigstore/rekor from 1.3.8 to 1.3.9 in the all group\n * Bump actions/setup-go from 5.2.0 to 5.3.0 in the all group\n * Bump golangci/golangci-lint-action from 6.1.1 to 6.2.0 in the all group\n * Bump sigs.k8s.io/release-utils from 0.8.5 to 0.9.0\n * Bump go dependencies manually\n * Bump ko-build/setup-ko from 0.7 to 0.8 in the all group\n * Bump actions/upload-artifact from 4.5.0 to 4.6.0 in the all group\n * Bump softprops/action-gh-release from 2.2.0 to 2.2.1 in the all group\n * Bump actions/upload-artifact from 4.4.3 to 4.5.0 in the all group\n * Bump golang.org/x/crypto from 0.28.0 to 0.31.0 in the go_modules group\n * Bump softprops/action-gh-release from 2.0.9 to 2.1.0 in the all group\n * Bump goreleaser/goreleaser-action from 6.0.0 to 6.1.0 in the all group\n * Bump softprops/action-gh-release from 2.0.8 to 2.0.9 in the all group\n * Update verify.yaml\n * Update release.yaml\n * Update ci-build-test.yaml\n * Bump actions/setup-go from 5.0.2 to 5.1.0 in the all group\n * Bump actions/checkout from 4.2.1 to 4.2.2 in the all group\n * Bump github.com/sigstore/sigstore from 1.8.9 to 1.8.10 in the all group\n * Bump actions/upload-artifact from 4.4.2 to 4.4.3 in the all group\n * Bump actions/upload-artifact from 4.4.1 to 4.4.2 in the all group\n * Bump sigstore/cosign-installer from 3.6.0 to 3.7.0 in the all group\n * Bump golangci/golangci-lint-action from 6.1.0 to 6.1.1 in the all group\n * Bump github.com/sigstore/cosign/v2 from 2.4.0 to 2.4.1 in the all group\n * Bump actions/checkout from 4.1.7 to 4.2.0 in the all group\n * Bump sigs.k8s.io/release-utils from 0.8.4 to 0.8.5 in the all group\n * upgrade to go1.23\n","affected":[{"package":{"name":"vexctl","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/vexctl&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.4+git20.5d61136-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"vexctl":"0.4.4+git20.5d61136-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21481-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1234486"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237611"},{"type":"REPORT","url":"https://bugzilla.suse.com/1238683"},{"type":"REPORT","url":"https://bugzilla.suse.com/1239186"},{"type":"REPORT","url":"https://bugzilla.suse.com/1239323"},{"type":"REPORT","url":"https://bugzilla.suse.com/1240444"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253802"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256535"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257138"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45337"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22868"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22869"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22870"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-27144"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-30204"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58181"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22772"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-24137"}]}