Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Ubuntu 26 Alpha Essential python-github-anotherpackage Upgrade 2025-78901-9

opensuse
Calendar Grey February 18, 2026
Dist Opensuse Esm H88
Critical openSUSE update addresses 3 serious issues in golang-github-prometheus, enhancing security. Immediate patch recommended.
An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.

Description

This update for golang-github-prometheus-prometheus fixes the following issues:

- CVE-2026-25547: Fixed an unbounded brace range expansion leading to excessive CPU and memory consumption. (bsc#1257841)

- CVE-2026-1615: Fixed arbitrary code injection due to unsafe evaluation of user-supplied JSON Path expressions in jsonpath. (bsc#1257897)

- CVE-2025-61140: Fixed a function vulnerable to prototype pollution in jsonpath. (bsc#1257442)

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-290=1

Patch

Package List

- openSUSE Leap 16.0:

golang-github-prometheus-prometheus-3.5.0-160000.2.1

References

* bsc#1257442

* bsc#1257841

* bsc#1257897

References:

* https://www.suse.com/security/cve/CVE-2025-61140.html

* https://www.suse.com/security/cve/CVE-2026-1615.html

* https://www.suse.com/security/cve/CVE-2026-25547.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:20239-1
Rating: critical
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here