{"id":"openSUSE-SU-2026:21613-1","summary":"Security update for bugwarden","details":"This update for bugwarden fixes the following issues:\n\nChanges in bugwarden:\n\n- Update to 0.5.0:\n  * Let the environment set allowed hosts and the auth header\n  * Require a bearer token on the HTTP transport\n  * Export audit records and diagnostics to an OTLP collector\n  * Handle SIGTERM so container stop is graceful\n  * Refuse unparsable allowed-hosts at startup\n  * Normalize tool schemas for Gemini/Vertex clients, and recurse\n    portable_schema into all draft-2020-12 positions\n\n- Vendored h2 bumped to 0.4.16 for RUSTSEC-2026-0258 /\n  GHSA-q83h-524g-xf6h (h2 unbounded empty DATA frames lead to\n  denial of service)\n\n- Ship the worked OpenTelemetry collector example as documentation\n","modified":"2026-08-23T18:23:37.653995382Z","published":"2026-08-20T14:16:08Z","references":[{"type":"ADVISORY"}],"affected":[{"package":{"name":"bugwarden","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/bugwarden&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.5.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"bugwarden":"0.5.0-bp160.1.1","bugwarden-bash-completion":"0.5.0-bp160.1.1","bugwarden-fish-completion":"0.5.0-bp160.1.1","bugwarden-zsh-completion":"0.5.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21613-1.json"}}],"schema_version":"1.9.0"}