openSUSE-SU-2026:21613-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21613-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21613-1
Published
2026-08-20T14:16:08Z
Modified
2026-08-23T18:23:37Z
Summary
Security update for bugwarden
Details

This update for bugwarden fixes the following issues:

Changes in bugwarden:

  • Update to 0.5.0:

    • Let the environment set allowed hosts and the auth header
    • Require a bearer token on the HTTP transport
    • Export audit records and diagnostics to an OTLP collector
    • Handle SIGTERM so container stop is graceful
    • Refuse unparsable allowed-hosts at startup
    • Normalize tool schemas for Gemini/Vertex clients, and recurse portable_schema into all draft-2020-12 positions
  • Vendored h2 bumped to 0.4.16 for RUSTSEC-2026-0258 / GHSA-q83h-524g-xf6h (h2 unbounded empty DATA frames lead to denial of service)

  • Ship the worked OpenTelemetry collector example as documentation

References

Affected packages

openSUSE:Leap 16.0 / bugwarden

Package

Name
bugwarden
Purl
pkg:rpm/opensuse/bugwarden&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.5.0-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "bugwarden":  "0.5.0-bp160.1.1",
            "bugwarden-bash-completion":  "0.5.0-bp160.1.1",
            "bugwarden-fish-completion":  "0.5.0-bp160.1.1",
            "bugwarden-zsh-completion":  "0.5.0-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21613-1.json"