{"id":"openSUSE-SU-2026:21557-1","summary":"Security update for gleam","details":"This update for gleam fixes the following issues:\n\nChanges in gleam:\n\n- Update to 1.18.1:\n  * CVE-2026-59247: insufficient verification of data authenticity\n    allows a MITM adversary to substitute forged Hex package\n    contents during dependency resolution (bsc#1272992)\n  * Set minimum required Erlang version to 26\n  * All features and bug fixes are extensively highlighted with\n    examples in upstream's blog post at\n    https://gleam.run/news/a-field-day-for-gleams-language-server/\n    and changelog at\n    https://github.com/gleam-lang/gleam/blob/v1.18.1/CHANGELOG.md .\n    Some of the highlights include:\n      - A lot of new features for the LSP\n      - Faster JavaScript using singletons\n      - Deprecation of ambiguous pipe syntax\n      - Path support in Git dependencies\n      - Up to 13% faster compilation\n      - Fixed various bugs in Erlang and JavaScript code\n        generation.\n      - Fixed several bugs in the float handling for the JavaScript\n        target.\n      - Fixed a bug in the generation of Erlang .app files.\n      - Fixed a bug where the formatter would produce invalid code.\n      - Fixed a bug in the TypeScript type definition generation.\n      - Fixed a bug where the compiler would evaluate the numerator\n        and denominator of a division in the wrong order.\n      - Fixed a bug where gleam docs would not be generated.\n","modified":"2026-08-12T18:23:42.474465357Z","published":"2026-08-10T10:55:07Z","related":["CVE-2026-59247"],"upstream":["CVE-2026-59247"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272992"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59247"}],"affected":[{"package":{"name":"gleam","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/gleam&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.18.1-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"gleam":"1.18.1-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21557-1.json"}}],"schema_version":"1.9.0"}