openSUSE 16 Security Update : golang-github-prometheus-alertmanager (openSUSE-SU-2026:22027-1)

medium Nessus Plugin ID 364115

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has a package installed that is affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:22027-1 advisory.

Changes in golang-github-prometheus-alertmanager:

- CVE-2026-39821: Fix validation bypass and privilege escalation by updating golang.org/x/net to version 0.57.0 (bsc#1266615)

- Update to version 0.33.1 (jsc#PED-16708):
* [BUGFIX] silences: fix silences snapshot missing legacy matchers field. This caused a bug that prevented older alertmanager versions from reading newer snapshots unnecessarily.
* [BUGFIX] silence with no matchers should populate an empty array in API response

- Update to version 0.33.0:
* The '--enable-feature=auto-gomaxprocs' option has been removed.
* Add a new Microsoft Teams integration that supports adaptive cards.
* Add support for AWS Signature V4 to call AWS services that require authentication.
* Add support for Google Chat as a notification channel.
* Add support for custom payloads in webhooks.

- Update to version 0.32.2:
* [BUGFIX] Fix dispatcher goroutine leaks on destroyed alertgroup swap.

- Update to version 0.32.1:
* [BUGFIX] dispatcher: Fix issue with dispatching to a contended route.

- Update to version 0.32.0:
* Reduce memory allocations through pre-sizing collections and batch allocation.
* CVE-2026-2303: Removed indirect dep on vulnerable mongodb driver (bsc#1269834)

- Update to version 0.31.1:
* No user-visible changes

- Update to version 0.31.0:
* Add full payload templating support for webhook notifier.
* Add support for UTF-8 label names in UI matchers.
* Fix escaping for matcher values with quotes in the UI.

- Update to version 0.30.1:
* [BUGFIX] Fix memory leak in tracing client.

- Update to version 0.30.0:
* Add Mattermost integration.
* Add support for Slack apps.
* Add distributed tracing support.
* Add names to inhibition rules.
* Add templating functions for working with URLs and JSON.
* Allow persistent peer names in a cluster.

- Update to version 0.29.0:
* Add incident.io notifier.
* Add monospace message formatting.
* Update Jira notifier to support both Jira cloud API v3 and Jira datacenter API v2.

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected golang-github-prometheus-alertmanager package.

See Also

https://bugzilla.suse.com/1266615

https://bugzilla.suse.com/1269834

https://www.suse.com/security/cve/CVE-2026-2303

https://www.suse.com/security/cve/CVE-2026-39821

Plugin Details

Severity: Medium

ID: 364115

File Name: openSUSE-2026-22027-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/8/2026

Updated: 10/8/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.8

Percentile: 57.96

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-39821

CVSS v3

Risk Factor: High

Base Score: 8.2

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Threat Score: 4.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-2303

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:golang-github-prometheus-alertmanager

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 10/6/2026

Vulnerability Publication Date: 2/10/2026

Reference Information

CVE: CVE-2026-2303, CVE-2026-39821