openSUSE-SU-2026:21277-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21277-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21277-1
Upstream
CVE (2)
Related
Published
2026-07-08T16:27:05Z
Modified
2026-07-11T18:24:35Z
Summary
Security update for go-sendxmpp
Details

This update for go-sendxmpp fixes the following issues:

Changes in go-sendxmpp:

  • Update to 0.16.0: Added:

    • Add Ox support to http-upload.
    • Add Ox support for private group chats.
    • Show error cause if joining MUCs failedi (requires go-xmpp >= v0.3.5). Changed:
    • Fix --ox-delete-nodes.
    • Fix receiving of 1-1 messages while joined in a MUC.
    • Use go-sendxmpp + a random ID as fallback MUC alias.
    • Strip leading "xmpp:" from recipients.
    • Strip trailing "?join" from MUC JIDs.
    • Add context for timeouts in stanza handling.
    • Check ID for disco items reply (requires go-xmpp >= v0.3.6).
    • Reduce channel buffer size to 1 where only one item will be returned.
    • Deprecate legacy PGP.
    • CVE-2026-1229: The CombinedMult function produces an incorrect value (bsc#1265538) Bump circl to 1.6.3
    • CVE-2026-39821: Failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266617) Bump net to 0.56.0
  • Update to 0.15.8:

    • Fix windows build (windows doesn't support syscalls Setgid and Setuid).
  • Update to 0.15.7:

    • Fix http-upload with legacy PGP encryption.
    • Fix reading of environment variables.
    • Fix a bug in looking up host meta 2.
    • Try to drop root privileges before connecting to the server.
    • Fix crash if a config key has no value.
    • Use a salt for stored FAST token.
    • Increase scrypt iterations for storing FAST token from 32768 to 65536.
    • Log a warning when --no-tls-verify or -n is set.
  • Update to 0.15.6: Added:

    • New config option allow_plain. Changed:
    • Explain each configuration option in manpage go-sendxmpp(5).
    • Improve config parsing robustness.
    • Update link in manpage as Gitlab calls issues now work items.
    • Recognize stanza size limit updates after authentication (via go-xmpp >= v0.3.3).
    • Tell connection target in error message when failing to connect.
  • Drop tar-scm service and use regular tarball and go_modules

  • Update to 0.15.5:

    • Fix SASL SCRAM Downgrade Protection in case of server providing different mechanisms for SASL and SASL2 (requires go-xmpp >0 v0.3.2).
  • Update to 0.15.4:

    • http-upload: Manually set content length for HTTP request (fixes issues with certain http modules/proxies).
  • Update to 0.15.3:

    • Fix PLAIN authentication for SASL2 (requires go-xmpp >= v0.3.1).
  • Update to 0.15.2:

    • Use UUIDv7 instead of UUIDv4 for stanza IDs (requires go-xmpp >= v0.2.19).
    • Fix stanza syntax error for legacy PGP messages.
    • Print error if legacy PGP and Ox are requested simultaneously.
    • Reworked OOB file sending and http-upload to use new functions from go-xmpp library (requires go-xmpp >= v0.3.0).
    • Try password login if FAST login fails.
References

Affected packages

openSUSE:Leap 16.0 / go-sendxmpp

Package

Name
go-sendxmpp
Purl
pkg:rpm/opensuse/go-sendxmpp&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.16.0-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "go-sendxmpp":  "0.16.0-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21277-1.json"