This update for go-sendxmpp fixes the following issues:
Update to 0.15.1:
- Added
* Add XEP-0359 Origin-ID to messages (requires go-xmpp >= v0.2.18).
- Changed
* HTTP upload: Ignore timeouts on disco IQs as some components do not
reply.
Upgrades the embedded golang.org/x/net to 0.46.0
* Fixes: boo#1251461, CVE-2025-47911: various algorithms with quadratic
complexity when parsing HTML documents
* Fixes: boo#1251677, CVE-2025-58190: excessive memory consumption by
'html.ParseFragment' when processing specially crafted input
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2025-483=1
- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):
go-sendxmpp-0.15.1-bp157.2.6.1
https://www.suse.com/security/cve/CVE-2025-47911.html
https://www.suse.com/security/cve/CVE-2025-58190.html
https://bugzilla.suse.com/1251461
https://bugzilla.suse.com/1251677
Get the latest Linux and open source security news straight to your inbox.