Security update for elemental-toolkit
This update for elemental-toolkit fixes the following issue - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260277). Changes for elemental-toolkit: - Update to version 2.1.6: * Bump golang.org/x/net to v0.55.0 (bsc#1267168) * Bump golang.org/x/crypto to v0.52.0 (bsc#1266187) * Update orange flavor * Install hugo from the OS repositories * Bump actions/upload-artifact to v7 * Bump actions/cache to v5 * Bump golangci/golangci-lint-action to v9 * Bump github.com/spf13/cobra library * Bump github.com/jaypipes/ghw library * Bump github.com/bramvdbogaerde/go-scp library * Bump google.golang.org/grpc library (bsc#1260277 CVE-2026-33186) * Bump github.com/ulikunitz/xz library * Do not clean cache on PRs from forks
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for elemental-toolkit fixes the following issue - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260277). Changes for elemental-toolkit: - Update to version 2.1.6: * Bump golang.org/x/net to v0.55.0 (bsc#1267168) * Bump golang.org/x/crypto to v0.52.0 (bsc#1266187) * Update orange flavor * Install hugo from the OS repositories * Bump actions/upload-artifact to v7 * Bump actions/cache to v5 * Bump golangci/golangci-lint-action to v9 * Bump github.com/spf13/cobra library * Bump github.com/jaypipes/ghw library * Bump github.com/bramvdbogaerde/go-scp library * Bump google.golang.org/grpc library (bsc#1260277 CVE-2026-33186) * Bump github.com/ulikunitz/xz library * Do not clean cache on PRs from forks
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1260277
- https://bugzilla.suse.com/1266187
- https://bugzilla.suse.com/1267168
- https://www.suse.com/security/cve/CVE-2026-25680
- https://www.suse.com/security/cve/CVE-2026-25681
- https://www.suse.com/security/cve/CVE-2026-27136
- https://www.suse.com/security/cve/CVE-2026-33186
- https://www.suse.com/security/cve/CVE-2026-39827
- https://www.suse.com/security/cve/CVE-2026-39828
- https://www.suse.com/security/cve/CVE-2026-39829
- https://www.suse.com/security/cve/CVE-2026-39830
- https://www.suse.com/security/cve/CVE-2026-39831
- https://www.suse.com/security/cve/CVE-2026-39832
- https://www.suse.com/security/cve/CVE-2026-39833
- https://www.suse.com/security/cve/CVE-2026-39834
- https://www.suse.com/security/cve/CVE-2026-39835
- https://www.suse.com/security/cve/CVE-2026-42502
- https://www.suse.com/security/cve/CVE-2026-42506
- https://www.suse.com/security/cve/CVE-2026-42508
- https://www.suse.com/security/cve/CVE-2026-46595
- https://www.suse.com/security/cve/CVE-2026-46597
- https://www.suse.com/security/cve/CVE-2026-46598
- https://www.suse.com/support/update/announcement/2026/suse-su-202622065-1/