FlawAtlas
Search the atlas
OPENSUSE-SU-2026:21281-1 Not scored

Security update for cosign

This update for cosign fixes the following issues - CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: multiple issues when parsing HTML files (bsc#1267044). - CVE-2026-33815: memory-safety vulnerability (bsc#1261811). - CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833,CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: Fixed multiple issues in golang.org/x/crypto/ssh. (bsc#1266049).

Exploit probability Not scored
Published July 10, 2026
Required by Not available
Last source change July 13, 2026

02 / AFFECTED SOFTWARE

Affected packages

openSUSE:Leap 16.0 cosign

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities openSUSE-SU-2026:21281-1

This update for cosign fixes the following issues - CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: multiple issues when parsing HTML files (bsc#1267044). - CVE-2026-33815: memory-safety vulnerability (bsc#1261811). - CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833,CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: Fixed multiple issues in golang.org/x/crypto/ssh. (bsc#1266049).

View original source

05 / REFERENCES

Further evidence