FlawAtlas
Search the atlas
SUSE-SU-2026:0592-1 Not scored

Security update for vexctl

This update for vexctl fixes the following issues: - Update to version 0.4.1+git78.f951e3a: - CVE-2025-22868: Unexpected memory consumption during token parsing in golang.org/x/oauth2. (bsc#1239186) - CVE-2024-45337: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto. (bsc#1234486) - CVE-2025-27144: Go JOSE's Parsing Vulnerable to Denial of Service. (bsc#1237611) - CVE-2025-22870: proxy bypass using IPv6 zone IDs. (bsc#1238683) - CVE-2025-22869: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh. (bsc#1239323) - CVE-2025-30204: jwt-go allows excessive memory allocation during header parsing. (bsc#1240444) - CVE-2025-58181: invalidated number of mechanisms can cause unbounded memory consumption. (bsc#1253802) - CVE-2026-22772: MetaIssuer URL validation bypass can trigger SSRF to arbitrary internal services. (bsc#1256535) - CVE-2026-24137: legacy TUF client allows for arbitrary file writes with target cache path traversal. (bsc#1257138)

Exploit probability Not scored
Published February 20, 2026
Required by Not available
Last source change February 21, 2026

02 / AFFECTED SOFTWARE

Affected packages

openSUSE:Leap 15.6 vexctl

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:0592-1

This update for vexctl fixes the following issues: - Update to version 0.4.1+git78.f951e3a: - CVE-2025-22868: Unexpected memory consumption during token parsing in golang.org/x/oauth2. (bsc#1239186) - CVE-2024-45337: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto. (bsc#1234486) - CVE-2025-27144: Go JOSE's Parsing Vulnerable to Denial of Service. (bsc#1237611) - CVE-2025-22870: proxy bypass using IPv6 zone IDs. (bsc#1238683) - CVE-2025-22869: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh. (bsc#1239323) - CVE-2025-30204: jwt-go allows excessive memory allocation during header parsing. (bsc#1240444) - CVE-2025-58181: invalidated number of mechanisms can cause unbounded memory consumption. (bsc#1253802) - CVE-2026-22772: MetaIssuer URL validation bypass can trigger SSRF to arbitrary internal services. (bsc#1256535) - CVE-2026-24137: legacy TUF client allows for arbitrary file writes with target cache path traversal. (bsc#1257138)

View original source

05 / REFERENCES

Further evidence