Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2285-1

Опубликовано: 05 июн. 2026
Источник: suse-cvrf

Описание

Security update for yq

This update for yq fixes the following issues:

  • CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html: multiple issues when parsing HTML files (bsc#1267053).
  • CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1267199).

Список пакетов

SUSE Linux Enterprise Module for Package Hub 15 SP7
yq-4.53.2-150500.3.9.1

Описание

Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:yq-4.53.2-150500.3.9.1

Ссылки

Описание

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:yq-4.53.2-150500.3.9.1

Ссылки

Описание

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:yq-4.53.2-150500.3.9.1

Ссылки

Описание

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:yq-4.53.2-150500.3.9.1

Ссылки

Описание

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:yq-4.53.2-150500.3.9.1

Ссылки

Описание

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:yq-4.53.2-150500.3.9.1

Ссылки
Уязвимость SUSE-SU-2026:2285-1