{"schema_version":"1.9.0","id":"openSUSE-SU-2026:21562-1","published":"2026-08-11T17:02:11Z","modified":"2026-08-12T17:45:23.327878690Z","related":["CVE-2026-39821"],"upstream":["CVE-2026-39821"],"summary":"Security update for go-sendxmpp","details":"This update for go-sendxmpp fixes the following issues:\n\nChanges in go-sendxmpp:\n\n- Update to 0.17.0:\n  * Add --ox-transfer-private-key to transfer the encrypted private key to PEP\n    to transfer it to other devices (requires go-xmpp >= v0.3.7).\n  * Add --ox-receive-private-key to receive the encrypted private key from PEP.\n  * Add config option no_root_warning.\n  * Add config option no_legacy_pgp_warning.\n  * Also disable legacy PGP when running as root (Ox was already disabled).\n  * Disable pinning for not using PLAIN when running as root.\n  * Add config option ox_trust_mode with settings blind and tofu.\n  * Due to new tofu trust mode for Ox, only one public key per contact is accepted for easier ID handling.\n  * Ox: Check that fingerprint of received key equals the advertised one.\n  * CVE-2026-39821: Failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266617): Bump net to 0.57.0\n","affected":[{"package":{"name":"go-sendxmpp","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/go-sendxmpp&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.17.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"go-sendxmpp":"0.17.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21562-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266617"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"}]}