openSUSE-SU-2026:21557-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21557-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21557-1
Upstream
Related
Published
2026-08-10T10:55:07Z
Modified
2026-08-12T18:23:42Z
Summary
Security update for gleam
Details

This update for gleam fixes the following issues:

Changes in gleam:

  • Update to 1.18.1:
    • CVE-2026-59247: insufficient verification of data authenticity allows a MITM adversary to substitute forged Hex package contents during dependency resolution (bsc#1272992)
    • Set minimum required Erlang version to 26
    • All features and bug fixes are extensively highlighted with examples in upstream's blog post at https://gleam.run/news/a-field-day-for-gleams-language-server/ and changelog at https://github.com/gleam-lang/gleam/blob/v1.18.1/CHANGELOG.md . Some of the highlights include:
      • A lot of new features for the LSP
      • Faster JavaScript using singletons
      • Deprecation of ambiguous pipe syntax
      • Path support in Git dependencies
      • Up to 13% faster compilation
      • Fixed various bugs in Erlang and JavaScript code generation.
      • Fixed several bugs in the float handling for the JavaScript target.
      • Fixed a bug in the generation of Erlang .app files.
      • Fixed a bug where the formatter would produce invalid code.
      • Fixed a bug in the TypeScript type definition generation.
      • Fixed a bug where the compiler would evaluate the numerator and denominator of a division in the wrong order.
      • Fixed a bug where gleam docs would not be generated.
References

Affected packages

openSUSE:Leap 16.0 / gleam

Package

Name
gleam
Purl
pkg:rpm/opensuse/gleam&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.18.1-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "gleam":  "1.18.1-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21557-1.json"