Security update for elemental-toolkit
This update for elemental-toolkit fixes the following issue - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260277). Changes for elemental-toolkit: - Update to v2.2.9: * 0e33b2bc Bump golang.org/x/net to v0.55.0 (bsc#1267168) * 4f5423b9 Bump golang.org/x/crypto to v0.52.0 (bsc#1266187) - Update to v2.2.8: * 3f38ae3e Avoid pulling binaries with curl * ef3f97a0 Bump golangci/golangci-lint-action to v9 * 34f9ed84 Bump github.com/spf13/cobra library * dff54d9a Bump github.com/jaypipes/ghw library * 7b7ba7ac github.com/bramvdbogaerde/go-scp libary * ac19e71c Bump google.golang.org/grpc library (bsc#1260277 CVE-2026-33186) * 55761782 Bump github.com/ulikunitz/xz library * d04e480d Update headers to 2026 * bb7974f4 Switch from TW to Leap 16.0 for green flavor
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for elemental-toolkit fixes the following issue - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260277). Changes for elemental-toolkit: - Update to v2.2.9: * 0e33b2bc Bump golang.org/x/net to v0.55.0 (bsc#1267168) * 4f5423b9 Bump golang.org/x/crypto to v0.52.0 (bsc#1266187) - Update to v2.2.8: * 3f38ae3e Avoid pulling binaries with curl * ef3f97a0 Bump golangci/golangci-lint-action to v9 * 34f9ed84 Bump github.com/spf13/cobra library * dff54d9a Bump github.com/jaypipes/ghw library * 7b7ba7ac github.com/bramvdbogaerde/go-scp libary * ac19e71c Bump google.golang.org/grpc library (bsc#1260277 CVE-2026-33186) * 55761782 Bump github.com/ulikunitz/xz library * d04e480d Update headers to 2026 * bb7974f4 Switch from TW to Leap 16.0 for green flavor
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1260277
- https://bugzilla.suse.com/1266187
- https://bugzilla.suse.com/1267168
- https://www.suse.com/security/cve/CVE-2026-25680
- https://www.suse.com/security/cve/CVE-2026-25681
- https://www.suse.com/security/cve/CVE-2026-27136
- https://www.suse.com/security/cve/CVE-2026-33186
- https://www.suse.com/security/cve/CVE-2026-39827
- https://www.suse.com/security/cve/CVE-2026-39828
- https://www.suse.com/security/cve/CVE-2026-39829
- https://www.suse.com/security/cve/CVE-2026-39830
- https://www.suse.com/security/cve/CVE-2026-39831
- https://www.suse.com/security/cve/CVE-2026-39832
- https://www.suse.com/security/cve/CVE-2026-39833
- https://www.suse.com/security/cve/CVE-2026-39834
- https://www.suse.com/security/cve/CVE-2026-39835
- https://www.suse.com/security/cve/CVE-2026-42502
- https://www.suse.com/security/cve/CVE-2026-42506
- https://www.suse.com/security/cve/CVE-2026-42508
- https://www.suse.com/security/cve/CVE-2026-46595
- https://www.suse.com/security/cve/CVE-2026-46597
- https://www.suse.com/security/cve/CVE-2026-46598
- https://www.suse.com/support/update/announcement/2026/suse-su-202622074-1/