Security update for containerized-data-importer
This update for containerized-data-importer fixes the following issues: Update to version 1.64.0. Security issues fixed: - CVE-2024-28180: improper handling of highly compressed data (bsc#1235204). - CVE-2024-45338: denial of service due to non-linear parsing of case-insensitive content (bsc#1235365). - CVE-2025-22868: unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239205).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for containerized-data-importer fixes the following issues: Update to version 1.64.0. Security issues fixed: - CVE-2024-28180: improper handling of highly compressed data (bsc#1235204). - CVE-2024-45338: denial of service due to non-linear parsing of case-insensitive content (bsc#1235365). - CVE-2025-22868: unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239205).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1235204
- https://bugzilla.suse.com/1235365
- https://bugzilla.suse.com/1239205
- https://www.suse.com/security/cve/CVE-2024-28180
- https://www.suse.com/security/cve/CVE-2024-45338
- https://www.suse.com/security/cve/CVE-2025-22868
- https://www.suse.com/support/update/announcement/2026/suse-su-202620550-1/