Synopsis
The remote openSUSE host is missing one or more security updates.
Description
The remote openSUSE 16 host has a package installed that is affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21481-1 advisory.
- CVE-2024-45337: golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (bsc#1234486).
- CVE-2025-22868: golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239186).
- CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239323).
- CVE-2025-22870: golang.org/x/net/proxy: proxy bypass using IPv6 zone IDs (bsc#1238683).
- CVE-2025-27144: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: Go JOSE's Parsing Vulnerable to Denial of Service (bsc#1237611).
- CVE-2025-30204: github.com/golang-jwt/jwt/v4: jwt-go allows excessive memory allocation during header parsing (bsc#1240444).
- CVE-2025-58181: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253802).
- CVE-2026-22772: github.com/sigstore/fulcio: bypass MetaIssuer URL validation bypass can trigger SSRF to arbitrary internal services (bsc#1256535).
- CVE-2026-24137: github.com/sigstore/sigstore/pkg/tuf: legacy TUF client allows for arbitrary file writes with target cache path traversal (bsc#1257138).
Changes for vexctl:
- Update to version 0.4.4+git20.5d61136:
* build(deps): Bump github.com/sigstore/cosign/v2
* build(deps): Bump actions/setup-go from 6.5.0 to 7.0.0
* build(deps): Bump the all group across 1 directory with 5 updates
* build(deps): Bump github.com/sigstore/rekor in the all group
* build(deps): Bump the all group with 4 updates
* build(deps): Bump github.com/google/go-containerregistry
* build(deps): Bump actions/setup-go from 6.4.0 to 6.5.0 in the all group
* build(deps): Bump the all group across 1 directory with 2 updates
* build(deps): Bump actions/checkout from 6.0.3 to 7.0.0
* build(deps): Bump chainguard-dev/actions in the all group
- Update to version 0.4.4:
* fix signature duplication
* fix lints
* housekeeping - deps update and ci cleanup
* build(deps): Bump the all group with 2 updates
* build(deps): Bump github.com/sigstore/sigstore in the all group
* build(deps): Bump golangci/golangci-lint-action in the all group
- Update to version 0.4.1+git147.b7e6ef0:
* build(deps): Bump goreleaser/goreleaser-action in the all group
* Bump sigstore/cosign-installer from 4.1.1 to 4.1.2 in the all group
* Bump chainguard-dev/actions from 1.6.17 to 1.6.19 in the all group
* Bump chainguard-dev/actions from 1.6.16 to 1.6.17 in the all group
* Bump github.com/package-url/packageurl-go in the all group
* Bump the all group with 2 updates
- Update to version 0.4.1+git133.efecaf7:
* Bump github.com/secure-systems-lab/go-securesystemslib
- Update to version 0.4.1+git129.c7f3066:
* Bump github.com/google/go-containerregistry in the all group
* Bump github.com/sigstore/timestamp-authority/v2 from 2.0.3 to 2.0.6
* Bump softprops/action-gh-release from 2.6.1 to 3.0.0
* Bump chainguard-dev/actions from 1.6.13 to 1.6.14 in the all group
* Bump actions/upload-artifact from 7.0.0 to 7.0.1 in the all group
* Bump github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3 in the all group
* Bump kubernetes-sigs/release-actions in the all group
* Bump github.com/in-toto/in-toto-golang from 0.9.0 to 0.10.0
* Bump the all group across 1 directory with 2 updates
* Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4
* fix(add): allow add without --product flag
* Use gomod version, bump linter
* Port vexctl to intoto/attestation
* Bump the all group across 1 directory with 5 updates
* Bump google.golang.org/grpc from 1.78.0 to 1.79.3
- Update to version 0.4.1+git96.558125d:
* Bump the all group across 1 directory with 3 updates
* Bump chainguard-dev/actions from 1.6.5 to 1.6.6 in the all group
* Bump github.com/google/go-containerregistry from 0.20.7 to 0.21.0
* Bump actions/upload-artifact from 6.0.0 to 7.0.0
* Bump goreleaser/goreleaser-action from 6.4.0 to 7.0.0
* Bump chainguard-dev/actions from 1.6.2 to 1.6.4 in the all group
- Update to version 0.4.1+git78.f951e3a:
* Bump chainguard-dev/actions from 1.6.1 to 1.6.2 in the all group
- Update to version 0.4.1+git76.10d7a2e:
* Bump chainguard-dev/actions from 1.6.0 to 1.6.1 in the all group
* Bump chainguard-dev/actions from 1.5.16 to 1.6.0 in the all group
* Bump chainguard-dev/actions from 1.5.14 to 1.5.16 in the all group
* Bump chainguard-dev/actions from 1.5.13 to 1.5.14 in the all group
* Bump github.com/sigstore/rekor from 1.4.3 to 1.5.0
* Bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to 2.4.1
* Bump actions/setup-go from 6.1.0 to 6.2.0 in the all group
* Bump github.com/sigstore/fulcio from 1.8.4 to 1.8.5
* Bump github.com/sigstore/cosign/v2 from 2.6.1 to 2.6.2 in the all group
* Bump chainguard-dev/actions from 1.5.10 to 1.5.11 in the all group
* Bump github.com/sigstore/fulcio from 1.7.1 to 1.8.3
* Bump github.com/sigstore/sigstore
* Bump actions/upload-artifact from 5.0.0 to 6.0.0
* bump golangci-lint
* update gorelease sing to works with cosign 3.0+
* Bump github.com/spf13/cobra from 1.10.1 to 1.10.2 in the all group
* Bump golangci/golangci-lint-action from 9.1.0 to 9.2.0 in the all group
* Bump actions/checkout from 6.0.0 to 6.0.1 in the all group
* Bump softprops/action-gh-release from 2.4.2 to 2.5.0 in the all group
* Bump chainguard-dev/actions from 1.5.9 to 1.5.10 in the all group
* Bump golangci/golangci-lint-action from 8.0.0 to 9.1.0
* Bump actions/checkout from 5.0.1 to 6.0.0
* Bump actions/setup-go from 6.0.0 to 6.1.0 in the all group
* Bump golang.org/x/crypto from 0.43.0 to 0.45.0
* Bump github.com/sigstore/rekor from 1.4.2 to 1.4.3 in the all group
* Bump actions/upload-artifact from 4.6.2 to 5.0.0
* Bump chainguard-dev/actions from 1.5.6 to 1.5.7 in the all group
* Bump sigstore/cosign-installer from 3.10.0 to 4.0.0
* Bump chainguard-dev/actions from 1.5.4 to 1.5.6 in the all group
* Bump softprops/action-gh-release from 2.3.4 to 2.4.0 in the all group
* Bump github.com/sigstore/cosign/v2 from 2.6.0 to 2.6.1 in the all group
- Update to version 0.4.1:
* Reverse platform+os naming scheme
- Update to version 0.4.0:
* update go, goreleaser and update/clean ci
* Bump sigs.k8s.io/release-utils from 0.12.1 to 0.12.2 in the all group
- Packaging improvements:
* Update to BuildRequires: golang(API) >= 1.25 matching go.mod
- Update to version 0.3.0+git181.33bac59:
* Bump sigstore/cosign-installer from 3.9.2 to 3.10.0 in the all group
* Fix break w/cosign 2.6.0
* Bump cosign & go-vex
* Fix 2.4 linter nits
* Bump softprops/action-gh-release from 2.3.2 to 2.3.3 in the all group
* Bump github.com/spf13/cobra from 1.9.1 to 1.10.1
* Bump actions/setup-go from 5.5.0 to 6.0.0
* Bump github.com/stretchr/testify from 1.11.0 to 1.11.1 in the all group
* Bump github.com/stretchr/testify from 1.10.0 to 1.11.0
* Bump github.com/go-viper/mapstructure/v2 in the go_modules group
* Bump goreleaser/goreleaser-action from 6.3.0 to 6.4.0 in the all group
* update release-utils and fix pkg name
* Bump actions/checkout from 4.2.2 to 5.0.0
* Bump github.com/secure-systems-lab/go-securesystemslib in the all group
* Bump github.com/sigstore/rekor from 1.3.10 to 1.4.0
* Bump sigs.k8s.io/release-utils from 0.11.1 to 0.12.0
* Bump sigstore/cosign-installer from 3.9.1 to 3.9.2 in the all group
* Bump github.com/sigstore/cosign/v2 from 2.5.2 to 2.5.3 in the all group
* Bump sigstore/cosign-installer from 3.9.0 to 3.9.1 in the all group
* Bump github.com/sigstore/cosign/v2 from 2.5.1 to 2.5.2 in the all group
* Bump sigstore/cosign-installer from 3.8.2 to 3.9.0 in the all group
* migrate config to v2
* Bump golangci/golangci-lint-action from 6.5.2 to 8.0.0
- Update to version 0.3.0+git133.ff97560:
* Bump softprops/action-gh-release from 2.3.0 to 2.3.2 in the all group
* Bump github.com/cloudflare/circl in the go_modules group
* Bump softprops/action-gh-release from 2.2.2 to 2.3.0 in the all group
* Bump actions/setup-go from 5.4.0 to 5.5.0 in the all group
* Bump github.com/sigstore/sigstore from 1.9.3 to 1.9.4 in the all group
* Bump sigstore/cosign-installer from 3.8.1 to 3.8.2 in the all group
* Bump softprops/action-gh-release from 2.2.1 to 2.2.2 in the all group
* Bump ko-build/setup-ko from 0.8 to 0.9 in the all group
* Bump github.com/sigstore/cosign/v2 from 2.4.3 to 2.5.0
* Bump goreleaser/goreleaser-action from 6.2.1 to 6.3.0 in the all group
* Bump sigs.k8s.io/release-utils from 0.11.0 to 0.11.1 in the all group
* Bump github.com/golang-jwt/jwt/v4 in the go_modules group
* Bump golangci/golangci-lint-action from 6.5.1 to 6.5.2 in the all group
* Bump github.com/sigstore/sigstore from 1.8.15 to 1.9.1
* Bump golang.org/x/net from 0.35.0 to 0.36.0 in the go_modules group
* Bump golangci/golangci-lint-action from 6.5.0 to 6.5.1 in the all group
* Bump github.com/go-jose/go-jose/v3 in the go_modules group
* Bump github.com/go-jose/go-jose/v4 in the go_modules group
* Bump actions/upload-artifact from 4.6.0 to 4.6.1 in the all group
* Bump sigstore/cosign-installer from 3.8.0 to 3.8.1 in the all group
* use go1.24 and update golangci-lint
* Bump golangci/golangci-lint-action from 6.3.3 to 6.5.0 in the all group
* Bump github.com/spf13/cobra from 1.8.1 to 1.9.1
* Bump github.com/sigstore/sigstore from 1.8.12 to 1.8.14 in the all group
* Bump golangci/golangci-lint-action from 6.3.2 to 6.3.3 in the all group
* Bump goreleaser/goreleaser-action from 6.1.0 to 6.2.1 in the all group
* Bump golangci/golangci-lint-action from 6.3.0 to 6.3.2 in the all group
* Bump sigstore/cosign-installer from 3.7.0 to 3.8.0 in the all group
* Bump golangci/golangci-lint-action from 6.2.0 to 6.3.0 in the all group
* Bump sigs.k8s.io/release-utils from 0.9.0 to 0.10.0
* Bump github.com/sigstore/rekor from 1.3.8 to 1.3.9 in the all group
* Bump actions/setup-go from 5.2.0 to 5.3.0 in the all group
* Bump golangci/golangci-lint-action from 6.1.1 to 6.2.0 in the all group
* Bump sigs.k8s.io/release-utils from 0.8.5 to 0.9.0
* Bump go dependencies manually
* Bump ko-build/setup-ko from 0.7 to 0.8 in the all group
* Bump actions/upload-artifact from 4.5.0 to 4.6.0 in the all group
* Bump softprops/action-gh-release from 2.2.0 to 2.2.1 in the all group
* Bump actions/upload-artifact from 4.4.3 to 4.5.0 in the all group
* Bump golang.org/x/crypto from 0.28.0 to 0.31.0 in the go_modules group
* Bump softprops/action-gh-release from 2.0.9 to 2.1.0 in the all group
* Bump goreleaser/goreleaser-action from 6.0.0 to 6.1.0 in the all group
* Bump softprops/action-gh-release from 2.0.8 to 2.0.9 in the all group
* Update verify.yaml
* Update release.yaml
* Update ci-build-test.yaml
* Bump actions/setup-go from 5.0.2 to 5.1.0 in the all group
* Bump actions/checkout from 4.2.1 to 4.2.2 in the all group
* Bump github.com/sigstore/sigstore from 1.8.9 to 1.8.10 in the all group
* Bump actions/upload-artifact from 4.4.2 to 4.4.3 in the all group
* Bump actions/upload-artifact from 4.4.1 to 4.4.2 in the all group
* Bump sigstore/cosign-installer from 3.6.0 to 3.7.0 in the all group
* Bump golangci/golangci-lint-action from 6.1.0 to 6.1.1 in the all group
* Bump github.com/sigstore/cosign/v2 from 2.4.0 to 2.4.1 in the all group
* Bump actions/checkout from 4.1.7 to 4.2.0 in the all group
* Bump sigs.k8s.io/release-utils from 0.8.4 to 0.8.5 in the all group
* upgrade to go1.23
Tenable has extracted the preceding description block directly from the SUSE security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected vexctl package.
Plugin Details
File Name: openSUSE-2026-21481-1.nasl
Agent: unix
Supported Sensors: Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C
Threat Vector: CVSS:4.0/E:P
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Vulnerability Information
CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:vexctl
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: Exploits are available
Patch Publication Date: 7/30/2026
Vulnerability Publication Date: 12/11/2024