openSUSE-SU-2026:21562-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21562-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21562-1
Upstream
Related
Published
2026-08-11T17:02:11Z
Modified
2026-08-12T17:45:23Z
Summary
Security update for go-sendxmpp
Details

This update for go-sendxmpp fixes the following issues:

Changes in go-sendxmpp:

  • Update to 0.17.0:
    • Add --ox-transfer-private-key to transfer the encrypted private key to PEP to transfer it to other devices (requires go-xmpp >= v0.3.7).
    • Add --ox-receive-private-key to receive the encrypted private key from PEP.
    • Add config option no_root_warning.
    • Add config option no_legacy_pgp_warning.
    • Also disable legacy PGP when running as root (Ox was already disabled).
    • Disable pinning for not using PLAIN when running as root.
    • Add config option ox_trust_mode with settings blind and tofu.
    • Due to new tofu trust mode for Ox, only one public key per contact is accepted for easier ID handling.
    • Ox: Check that fingerprint of received key equals the advertised one.
    • CVE-2026-39821: Failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266617): Bump net to 0.57.0
References

Affected packages

openSUSE:Leap 16.0 / go-sendxmpp

Package

Name
go-sendxmpp
Purl
pkg:rpm/opensuse/go-sendxmpp&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.17.0-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "go-sendxmpp":  "0.17.0-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21562-1.json"