{"id":"openSUSE-SU-2026:22010-1","summary":"Security update for distribution","details":"This update for distribution fixes the following issues:\n\n- CVE-2026-81871: go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass\n  allows log telemetry interception and alteration (bsc#1281468).\n- CVE-2026-81872: go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission\n  (bsc#1281469).\n","modified":"2026-10-03T17:23:10.838475594Z","published":"2026-10-01T12:14:32Z","related":["CVE-2026-81871","CVE-2026-81872"],"upstream":["CVE-2026-81871","CVE-2026-81872"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281468"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281469"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-81871"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-81872"}],"affected":[{"package":{"name":"distribution","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/distribution&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.1-160000.4.1"}]}],"ecosystem_specific":{"binaries":[{"distribution-registry":"3.1.1-160000.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:22010-1.json"}}],"schema_version":"1.9.0"}