openSUSE-SU-2026:21367-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21367-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21367-1
Upstream
CVE (9)
Related
Published
2026-07-17T12:53:41Z
Modified
2026-07-19T18:24:10Z
Summary
Security update for lux
Details

This update for lux fixes the following issues:

Changes in lux:

  • CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506: Issues when parsing HTML files (bsc#1267110)

  • CVE-2024-45338: Denial of service due to non-linear parsing of case-insensitive content (bsc#1235304)

  • CVE-2025-22872: Incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction (bsc#1241766)

  • CVE-2025-47911: Various algorithms with quadratic complexity when parsing HTML documents (bsc#1251460)

  • CVE-2025-58190: Excessive memory consumption (bsc#1251627) Bump x/net to 0.57.0

  • Update to 0.24.1:

    • ci: bump go version to 1.22 #1350
References

Affected packages

openSUSE:Leap 16.0 / lux

Package

Name
lux
Purl
pkg:rpm/opensuse/lux&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.24.1-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "lux":  "0.24.1-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21367-1.json"