rpm package
opensuse/alloy&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/alloy&distro=openSUSE%20Tumbleweed
Vulnerabilities (55)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-48496 | Med | 6.2 | < 1.19.2-1.1 | 1.19.2-1.1 | Sep 11, 2026 | OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to open a nonregular mapping file, such as a FI | |
| CVE-2026-89090 | Med | 5.9 | < 1.19.2-1.1 | 1.19.2-1.1 | Sep 11, 2026 | An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outsid | |
| CVE-2026-56854 | Hig | 7.5 | < 1.19.2-1.1 | 1.19.2-1.1 | Aug 28, 2026 | The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCal | |
| CVE-2026-37236 | Cri | 9.8 | < 1.19.2-1.1 | 1.19.2-1.1 | Aug 28, 2026 | grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the | |
| CVE-2026-81521 | Med | 6.5 | < 1.19.2-1.1 | 1.19.2-1.1 | Aug 27, 2026 | The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input a | |
| CVE-2026-75889 | Hig | 7.7 | < 1.19.2-1.1 | 1.19.2-1.1 | Aug 27, 2026 | Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file through bearerTokenFile. Alloy reads the file and sends its contents as a bearer token to an att | |
| CVE-2026-75890 | — | < 1.19.2-1.1 | 1.19.2-1.1 | Aug 18, 2026 | Rejected reason: Duplicate of CVE-2026-50236. This CVE ID was reserved in error for a finding that already had an existing CVE assignment. | ||
| CVE-2026-71557 | Med | 6.3 | < 1.19.2-1.1 | 1.19.2-1.1 | Aug 7, 2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example con | |
| CVE-2026-71556 | Hig | 7.1 | < 1.19.2-1.1 | 1.19.2-1.1 | Aug 7, 2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a malicious | |
| CVE-2026-56852 | Hig | 7.5 | < 1.19.2-1.1 | 1.19.2-1.1 | Jul 21, 2026 | A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. | |
| CVE-2026-46600 | Hig | 7.5 | < 1.19.2-1.1 | 1.19.2-1.1 | Jul 21, 2026 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. | |
| CVE-2026-41178 | Med | 5.3 | < 1.19.2-1.1 | 1.19.2-1.1 | Jun 4, 2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the iss | |
| CVE-2026-10722 | Low | 3.3 | < 1.17.1-1.1 | 1.17.1-1.1 | Jun 3, 2026 | A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be pe | |
| CVE-2026-45686 | Hig | 7.5 | < 1.17.0-1.1 | 1.17.0-1.1 | Jun 2, 2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's memcached text protocol parser can crash the OBI process and cause denial of service. W | |
| CVE-2026-45685 | Hig | 7.5 | < 1.17.0-1.1 | 1.17.0-1.1 | Jun 2, 2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught panics in the MongoDB TCP parser, allowing a remote unauthenticated attacker to c | |
| CVE-2026-45684 | Med | 4.9 | < 1.19.2-1.1 | 1.19.2-1.1 | Jun 2, 2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by reading only the first iovec entry but using the total iov_iter.count as the copy leng | |
| CVE-2026-45683 | Low | 3.8 | < 1.19.2-1.1 | 1.19.2-1.1 | Jun 2, 2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with bpf_probe_read instead of bpf_probe_read_user. An instrumented local process can theref | |
| CVE-2026-45682 | Med | 5.1 | < 1.17.0-1.1 | 1.17.0-1.1 | Jun 2, 2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the custom CappedConcurrentHashMap introduced for Java TLS state tracking never removes keys from its insertion-order queue when entries are deleted. In l | |
| CVE-2026-45681 | Med | 5.9 | < 1.19.2-1.1 | 1.19.2-1.1 | Jun 2, 2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the per-CPU message-buffer fallback path uses a 256-byte backup buffer but preserves the original payload size, which can be up to 8KB. If a CPU mismatch | |
| CVE-2026-45680 | Med | 5.9 | < 1.19.2-1.1 | 1.19.2-1.1 | Jun 2, 2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI replays BPF probe hits into histogram observations by looping once per recorded run count. On busy systems, the run-count delta can become very large, |
- affected < 1.19.2-1.1fixed 1.19.2-1.1
OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to open a nonregular mapping file, such as a FI
- affected < 1.19.2-1.1fixed 1.19.2-1.1
An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outsid
- affected < 1.19.2-1.1fixed 1.19.2-1.1
The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCal
- affected < 1.19.2-1.1fixed 1.19.2-1.1
grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the
- affected < 1.19.2-1.1fixed 1.19.2-1.1
The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input a
- affected < 1.19.2-1.1fixed 1.19.2-1.1
Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file through bearerTokenFile. Alloy reads the file and sends its contents as a bearer token to an att
- CVE-2026-75890Aug 18, 2026affected < 1.19.2-1.1fixed 1.19.2-1.1
Rejected reason: Duplicate of CVE-2026-50236. This CVE ID was reserved in error for a finding that already had an existing CVE assignment.
- affected < 1.19.2-1.1fixed 1.19.2-1.1
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example con
- affected < 1.19.2-1.1fixed 1.19.2-1.1
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a malicious
- affected < 1.19.2-1.1fixed 1.19.2-1.1
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
- affected < 1.19.2-1.1fixed 1.19.2-1.1
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
- affected < 1.19.2-1.1fixed 1.19.2-1.1
OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the iss
- affected < 1.17.1-1.1fixed 1.17.1-1.1
A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be pe
- affected < 1.17.0-1.1fixed 1.17.0-1.1
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's memcached text protocol parser can crash the OBI process and cause denial of service. W
- affected < 1.17.0-1.1fixed 1.17.0-1.1
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught panics in the MongoDB TCP parser, allowing a remote unauthenticated attacker to c
- affected < 1.19.2-1.1fixed 1.19.2-1.1
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by reading only the first iovec entry but using the total iov_iter.count as the copy leng
- affected < 1.19.2-1.1fixed 1.19.2-1.1
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with bpf_probe_read instead of bpf_probe_read_user. An instrumented local process can theref
- affected < 1.17.0-1.1fixed 1.17.0-1.1
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the custom CappedConcurrentHashMap introduced for Java TLS state tracking never removes keys from its insertion-order queue when entries are deleted. In l
- affected < 1.19.2-1.1fixed 1.19.2-1.1
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the per-CPU message-buffer fallback path uses a 256-byte backup buffer but preserves the original payload size, which can be up to 8KB. If a CPU mismatch
- affected < 1.19.2-1.1fixed 1.19.2-1.1
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI replays BPF probe hits into histogram observations by looping once per recorded run count. On busy systems, the run-count delta can become very large,
Page 1 of 3