Security update for alloy
This update for alloy fixes the following issues Security issues: - CVE-2026-4427: github.com/jackc/pgproto3/v2: improper validation of field length allows a malicious PostgreSQL server to crash a client application via a DataRow message (bsc#1259919). - CVE-2026-25934: github.com/go-git/go-git/v5: improper verification of data integrity values for .pack and .idx files can lead to the consumption of corrupted files (bsc#1258099). - CVE-2026-26958: filippo.io/edwards25519: failure to initialize receiver in MultiScalarMult can produce invalid results and lead to undefined behavior (bsc#1258609). - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo- header (bsc#1260317). Non security issue: - Updated to 1.16.0 - Use systemd tmpfiles.d to create /var/lib/alloy hierarchy (jsc#PED-14815)
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for alloy fixes the following issues Security issues: - CVE-2026-4427: github.com/jackc/pgproto3/v2: improper validation of field length allows a malicious PostgreSQL server to crash a client application via a DataRow message (bsc#1259919). - CVE-2026-25934: github.com/go-git/go-git/v5: improper verification of data integrity values for .pack and .idx files can lead to the consumption of corrupted files (bsc#1258099). - CVE-2026-26958: filippo.io/edwards25519: failure to initialize receiver in MultiScalarMult can produce invalid results and lead to undefined behavior (bsc#1258609). - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo- header (bsc#1260317). Non security issue: - Updated to 1.16.0 - Use systemd tmpfiles.d to create /var/lib/alloy hierarchy (jsc#PED-14815)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1258099
- https://bugzilla.suse.com/1258609
- https://bugzilla.suse.com/1259919
- https://bugzilla.suse.com/1260317
- https://www.suse.com/security/cve/CVE-2026-25934
- https://www.suse.com/security/cve/CVE-2026-26958
- https://www.suse.com/security/cve/CVE-2026-33186
- https://www.suse.com/security/cve/CVE-2026-4427
- https://www.suse.com/support/update/announcement/2026/suse-su-202621793-1/