Security update for lux
This update for lux fixes the following issues: Changes in lux: - CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506: Issues when parsing HTML files (bsc#1267110) - CVE-2024-45338: Denial of service due to non-linear parsing of case-insensitive content (bsc#1235304) - CVE-2025-22872: Incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction (bsc#1241766) - CVE-2025-47911: Various algorithms with quadratic complexity when parsing HTML documents (bsc#1251460) - CVE-2025-58190: Excessive memory consumption (bsc#1251627) Bump x/net to 0.57.0 - Update to 0.24.1: * ci: bump go version to 1.22 #1350
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for lux fixes the following issues: Changes in lux: - CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506: Issues when parsing HTML files (bsc#1267110) - CVE-2024-45338: Denial of service due to non-linear parsing of case-insensitive content (bsc#1235304) - CVE-2025-22872: Incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction (bsc#1241766) - CVE-2025-47911: Various algorithms with quadratic complexity when parsing HTML documents (bsc#1251460) - CVE-2025-58190: Excessive memory consumption (bsc#1251627) Bump x/net to 0.57.0 - Update to 0.24.1: * ci: bump go version to 1.22 #1350
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1235304
- https://bugzilla.suse.com/1241766
- https://bugzilla.suse.com/1251460
- https://bugzilla.suse.com/1251627
- https://bugzilla.suse.com/1267110
- https://www.suse.com/security/cve/CVE-2024-45338
- https://www.suse.com/security/cve/CVE-2025-22872
- https://www.suse.com/security/cve/CVE-2025-47911
- https://www.suse.com/security/cve/CVE-2025-58190
- https://www.suse.com/security/cve/CVE-2026-25680
- https://www.suse.com/security/cve/CVE-2026-25681
- https://www.suse.com/security/cve/CVE-2026-27136
- https://www.suse.com/security/cve/CVE-2026-42502
- https://www.suse.com/security/cve/CVE-2026-42506