openSUSE-SU-2026:21613-1: moderate: Security update for bugwarden

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for bugwarden
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21613-1
Rating: moderate


Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves various issues can now be installed.

Description:

This update for bugwarden fixes the following issues:

Changes in bugwarden:

- Update to 0.5.0:
  * Let the environment set allowed hosts and the auth header
  * Require a bearer token on the HTTP transport
  * Export audit records and diagnostics to an OTLP collector
  * Handle SIGTERM so container stop is graceful
  * Refuse unparsable allowed-hosts at startup
  * Normalize tool schemas for Gemini/Vertex clients, and recurse
    portable_schema into all draft-2020-12 positions

- Vendored h2 bumped to 0.4.16 for RUSTSEC-2026-0258 /
  GHSA-q83h-524g-xf6h (h2 unbounded empty DATA frames lead to
  denial of service)

- Ship the worked OpenTelemetry collector example as documentation


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-packagehub-514=1

Package List:

- openSUSE Leap 16.0:

  bugwarden-0.5.0-bp160.1.1
  bugwarden-bash-completion-0.5.0-bp160.1.1
  bugwarden-fish-completion-0.5.0-bp160.1.1
  bugwarden-zsh-completion-0.5.0-bp160.1.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.