FlawAtlas
Search the atlas
SUSE-SU-2026:1951-1 Not scored

Security update for zypper-docker

This update for zypper-docker fixes the following issues - CVE-2026-2808: github.com/hashicorp/consul: unvalidated user-supplied file paths can lead to arbitrary file reads through the Vault Kubernetes authentication provider (bsc#1259563). - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo- header (bsc#1260086). Changes for zypper-docker: - Bump to version 2.0.2 * update vendor provided docker to v28.5.2 * update go sources to use new docker api * update vendor directory to reflect docker update - Bump to version 2.0.1 * Fix golint import path * migrate to go 1.11 module * ci: use registry.opensuse.org

Exploit probability Not scored
Published May 18, 2026
Required by Not available
Last source change May 19, 2026

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:1951-1

This update for zypper-docker fixes the following issues - CVE-2026-2808: github.com/hashicorp/consul: unvalidated user-supplied file paths can lead to arbitrary file reads through the Vault Kubernetes authentication provider (bsc#1259563). - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo- header (bsc#1260086). Changes for zypper-docker: - Bump to version 2.0.2 * update vendor provided docker to v28.5.2 * update go sources to use new docker api * update vendor directory to reflect docker update - Bump to version 2.0.1 * Fix golint import path * migrate to go 1.11 module * ci: use registry.opensuse.org

View original source

05 / REFERENCES

Further evidence