openSUSE-SU-2026:20584-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20584-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20584-1
Upstream
Related
Published
2026-04-16T12:46:59Z
Modified
2026-04-22T18:27:19Z
Summary
Security update for v2ray-core
Details

This update for v2ray-core fixes the following issues:

Changes in v2ray-core:

  • Update version to 5.47.0

    • Add sticky choice option for leastping
    • Add support for enrollment links in tlsmirror
    • Add Wireguard Outbound (unreleased)
    • Add sticky choice option for leastping
    • Generalize IP address parsing in TUN stack options
    • Fix bugs
  • CVE-2026-33186: google.golang.org/grpc: Fixed authorization bypass caused by improper validation of the HTTP/2 :path pseudo-header (boo#1260329)

  • Update version to 5.44.1

    • uTLS: bundled library updated to v1.8.2 for Chrome120 imitation profile identification
    • Update golang toolchain to v1.25.6, which fixed an vulnerable (tls.Config).Clone function
    • Fix bugs
  • Update version to 5.42.0

    • Add TLSMirror bootstrap enrollment and self enrollment feature
    • TLSMirror Inverse Role Request Tripper Enrollment Server Support
References

Affected packages

openSUSE:Leap 16.0 / v2ray-core

Package

Name
v2ray-core
Purl
pkg:rpm/opensuse/v2ray-core&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.47.0-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "golang-github-v2fly-v2ray-core":  "5.47.0-bp160.1.1",
            "v2ray-core":  "5.47.0-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20584-1.json"