Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package grafana for openSUSE:Factory checked in at 2026-08-27 18:56:06 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/grafana (Old) and /work/SRC/openSUSE:Factory/.grafana.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "grafana" Thu Aug 27 18:56:06 2026 rev:94 rq:1374090 version:12.4.5 Changes: -------- --- /work/SRC/openSUSE:Factory/grafana/grafana.changes 2026-07-22 19:08:51.876783823 +0200 +++ /work/SRC/openSUSE:Factory/.grafana.new.1265/grafana.changes 2026-08-27 18:57:31.881580706 +0200 @@ -19,0 +20,3 @@ + CVE-2026-39882: Prevent memory exhaustion DoS in OpenTelemetry + OTLP HTTP exporters by updating to v1.43.0. + (bsc#1274217) @@ -25,0 +29,9 @@ + CVE-2026-9029: Fix arbitrary code execution and information + disclosure via XSS in geomap panel (bsc#1272328) + CVE-2026-41607: Fix out-of-bounds read and potential + information disclosure in Apache Thrift + (bsc#1263289) + CVE-2026-33814: Fix infinite loop in HTTP/2 transport by + updating golang.org/x/net (bsc#1265763) + CVE-2026-8609: Fix pre-authentication DoS in the OAuth login + route (bsc#1271330) @@ -38,0 +51,3 @@ + * CVE-2026-1229: Update github.com/cloudflare/circl to fix + producing incorect output for specific inputs + (bsc#1265525) @@ -54,0 +70,2 @@ + * CVE-2026-21723: Fix DoS vulnerability in Templates Test + endpoint (bsc#1272427) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------
