FlawAtlas
Search the atlas
SUSE-SU-2026:3327-1 Not scored

Security update for yq

This update for yq fixes the following issues: Update to v4.53.3. - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1267199). - CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of input containing invalid UTF-8 bytes can lead to infinite loop (bsc#1271994). Changes for yq: - v4.53.3: * Add --ini-preserve-quotes flag for INI round-trip quote preservation. * Fix: reset INI decoder state on init. * Fix: decode properties array bracket paths. * Fix: preserve floats with trailing zero when encoding YAML to JSON. * Fix: JSON to TOML root scope and null handling. * Fix: reset TOML decoder finished flag on Init for multi-doc evaluation. * Fix: reset TOML decoder between files when evaluating all at once. * Fix: preserve TOML inline table array scope. * Fix: preserve empty TOML arrays in tables * Fix: TOML encoder uses inline tables for YAML FlowStyle mappings. * Fix nested inline YAML merge explode. * Fix repeatString overflow test on 32-bit platforms.

Exploit probability Not scored
Published July 28, 2026
Required by Not available
Last source change July 29, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for Package Hub 15 SP7 yq

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:3327-1

This update for yq fixes the following issues: Update to v4.53.3. - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1267199). - CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of input containing invalid UTF-8 bytes can lead to infinite loop (bsc#1271994). Changes for yq: - v4.53.3: * Add --ini-preserve-quotes flag for INI round-trip quote preservation. * Fix: reset INI decoder state on init. * Fix: decode properties array bracket paths. * Fix: preserve floats with trailing zero when encoding YAML to JSON. * Fix: JSON to TOML root scope and null handling. * Fix: reset TOML decoder finished flag on Init for multi-doc evaluation. * Fix: reset TOML decoder between files when evaluating all at once. * Fix: preserve TOML inline table array scope. * Fix: preserve empty TOML arrays in tables * Fix: TOML encoder uses inline tables for YAML FlowStyle mappings. * Fix nested inline YAML merge explode. * Fix repeatString overflow test on 32-bit platforms.

View original source

05 / REFERENCES

Further evidence