FlawAtlas
Search the atlas
OPENSUSE-SU-2026:21562-1 Not scored

Security update for go-sendxmpp

This update for go-sendxmpp fixes the following issues: Changes in go-sendxmpp: - Update to 0.17.0: * Add --ox-transfer-private-key to transfer the encrypted private key to PEP to transfer it to other devices (requires go-xmpp >= v0.3.7). * Add --ox-receive-private-key to receive the encrypted private key from PEP. * Add config option no_root_warning. * Add config option no_legacy_pgp_warning. * Also disable legacy PGP when running as root (Ox was already disabled). * Disable pinning for not using PLAIN when running as root. * Add config option ox_trust_mode with settings blind and tofu. * Due to new tofu trust mode for Ox, only one public key per contact is accepted for easier ID handling. * Ox: Check that fingerprint of received key equals the advertised one. * CVE-2026-39821: Failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266617): Bump net to 0.57.0

Exploit probability Not scored
Published August 11, 2026
Required by Not available
Last source change August 12, 2026

02 / AFFECTED SOFTWARE

Affected packages

openSUSE:Leap 16.0 go-sendxmpp

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities openSUSE-SU-2026:21562-1

This update for go-sendxmpp fixes the following issues: Changes in go-sendxmpp: - Update to 0.17.0: * Add --ox-transfer-private-key to transfer the encrypted private key to PEP to transfer it to other devices (requires go-xmpp >= v0.3.7). * Add --ox-receive-private-key to receive the encrypted private key from PEP. * Add config option no_root_warning. * Add config option no_legacy_pgp_warning. * Also disable legacy PGP when running as root (Ox was already disabled). * Disable pinning for not using PLAIN when running as root. * Add config option ox_trust_mode with settings blind and tofu. * Due to new tofu trust mode for Ox, only one public key per contact is accepted for easier ID handling. * Ox: Check that fingerprint of received key equals the advertised one. * CVE-2026-39821: Failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266617): Bump net to 0.57.0

View original source

05 / REFERENCES

Further evidence