Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

openSUSE 16.0: go-sendxmpp Moderate Security Update 2026:20058-1

opensuse
Calendar Grey January 18, 2026
Dist Opensuse Esm H88
A moderate security update for openSUSE fixing three vulnerabilities in go-sendxmpp with detailed patch instructions included.
An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.

Description

This update for go-sendxmpp fixes the following issues:

Changes in go-sendxmpp:

- Update to 0.15.1:

Added

* Add XEP-0359 Origin-ID to messages (requires go-xmpp >= v0.2.18).

Changed

* HTTP upload: Ignore timeouts on disco IQs as some components do

not reply.

- Upgrades the embedded golang.org/x/net to 0.46.0

* Fixes: bsc#1251461, CVE-2025-47911: various algorithms with

quadratic complexity when parsing HTML documents

* Fixes: bsc#1251677, CVE-2025-58190: excessive memory consumption

by 'html.ParseFragment' when processing specially crafted input

- Update to 0.15.0:

Added:

* Add flag --verbose to show debug information.

* Add flag --recipients to specify recipients by file.

* Add flag --retry-connect to try after a waiting time if the connection fails.

* Add flag --retry-connect-max to specify the amount of retry attempts.

* Add flag --legacy-pgp for using XEP-0027 PGP encryption with Ox keys.

* Add support for punycode domains.

Changed:

*...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

go-sendxmpp-0.15.1-bp160.1.1

References

* bsc#1241814

* bsc#1251461

* bsc#1251677

References:

* https://www.suse.com/security/cve/CVE-2025-22872.html

* https://www.suse.com/security/cve/CVE-2025-47911.html

* https://www.suse.com/security/cve/CVE-2025-58190.html

Announcement ID: openSUSE-SU-2026:20058-1
Rating: moderate
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here