This update for golang-github-prometheus-prometheus fixes the following issues:
- CVE-2026-25547: Fixed an unbounded brace range expansion leading to excessive CPU and memory consumption. (bsc#1257841)
- CVE-2026-1615: Fixed arbitrary code injection due to unsafe evaluation of user-supplied JSON Path expressions in jsonpath. (bsc#1257897)
- CVE-2025-61140: Fixed a function vulnerable to prototype pollution in jsonpath. (bsc#1257442)
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-290=1
- openSUSE Leap 16.0:
golang-github-prometheus-prometheus-3.5.0-160000.2.1
* bsc#1257442
* bsc#1257841
* bsc#1257897
References:
* https://www.suse.com/security/cve/CVE-2025-61140.html
* https://www.suse.com/security/cve/CVE-2026-1615.html
* https://www.suse.com/security/cve/CVE-2026-25547.html
Get the latest Linux and open source security news straight to your inbox.