CODERED VTA

openSUSE Patches Four Bundled Go Library Flaws in Prometheus Blackbox Exporter

High
Cybersecurity concept with a lock
Photo by Adi Goldstein on Unsplash

openSUSE has issued advisory openSUSE-SU-2026:22026-1, rated important, which resolves four vulnerabilities and four bug fixes in prometheus-blackbox_exporter on openSUSE Leap 16.0. The four CVEs addressed are CVE-2023-45288, CVE-2025-22870, CVE-2026-39821 and CVE-2026-84304, all of them carried into the exporter through bundled Go libraries rather than the exporter's own source. The fixed package is prometheus-blackbox_exporter-0.26.0-bp160.1.1, delivered through patch identifier openSUSE-Leap-16.0-packagehub-654. Only openSUSE Leap 16.0 is named as an affected product in this advisory.

All four issues sit in Go libraries compiled into the exporter rather than in the exporter's own probe logic, which is why they arrive as dependency bumps rather than code rewrites. CVE-2026-84304, scored 7.5 under CVSS v3.1 and 8.7 under CVSS v4.0, is a heap memory exhaustion condition reached through HTTP/2 DATA frame fragmentation in gRPC-Go, and is addressed by moving that library to version 1.83.1. CVE-2026-39821, scored 7.4 and 9.1 respectively, is described as a potential validation bypass leading to privilege escalation and is closed by raising golang.org/x/net to version 0.57.0, following an earlier interim bump to 0.55.0. The two older issues are CVE-2025-22870, a proxy bypass achieved using IPv6 zone identifiers, and CVE-2023-45288, a failure to close connections when an excessive number of headers is received. The advisory does not publish proof-of-concept detail or exploitation telemetry for any of the four, so the mechanisms above are the limit of what the vendor has described.

Blackbox exporter instances typically sit inside monitoring infrastructure with network reachability to both scrapers and probe targets, which makes an unauthenticated availability flaw such as CVE-2026-84304 more consequential than its placement in a monitoring tool suggests — an exporter killed by the out-of-memory handler takes observability down at precisely the moment operators need it. The validation bypass in CVE-2026-39821 carries high confidentiality and integrity ratings and requires no privileges, though the vendor notes attack complexity is not trivial. On current exploitation data, CVE-2023-45288 stands out sharply with a 92.0% probability of exploitation in the next 30 days per FIRST EPSS, while CVE-2025-22870 sits at 0.4%, CVE-2026-39821 at 0.7% and CVE-2026-84304 at 0.6%. None of the four is reported as exploited in the wild in this advisory. The broader exposure is that the same gRPC-Go and golang.org/x/net versions are statically linked into many other Go-based agents and exporters, so a single patched package rarely closes the whole problem on a given host.

Attack Surface

Infrastructure, Supply Chain (Third-party vendors), Server OS

Tactics

Impact, Privilege Escalation, Defense Evasion

Techniques

  • T1499 – Endpoint Denial of Service
  • T1499.003 – Application Exhaustion Flood
  • T1068 – Exploitation for Privilege Escalation
  • T1090 – Proxy

SuperPRO's Threat Countermeasures Procedures

  1. Upgrade prometheus-blackbox_exporter on openSUSE Leap 16.0 to 0.26.0-bp160.1.1 by running 'zypper in -t patch openSUSE-Leap-16.0-packagehub-654=1', or apply the update through YaST online_update or 'zypper patch'.
  2. Inventory every Go-built agent, exporter and service on Leap 16.0 hosts for statically linked gRPC-Go below 1.83.1 (CVE-2026-84304) and golang.org/x/net below 0.57.0 (CVE-2026-39821), since these dependencies are compiled in and are not fixed by updating blackbox_exporter alone.
  3. Restrict inbound access to the blackbox exporter listener (default TCP/9115) with firewalld or host ACLs so only authorised Prometheus scrapers can reach the /probe and /metrics endpoints, limiting who can send the fragmented HTTP/2 DATA frames behind CVE-2026-84304.
  4. Add alerting for the blackbox_exporter process being terminated by the kernel OOM killer and for sustained resident-memory growth on the exporter host, as heap memory exhaustion is the stated impact of CVE-2026-84304.
  5. Enforce outbound restrictions at the egress proxy or firewall rather than relying on client-side NO_PROXY and HTTP_PROXY handling, because CVE-2025-22870 allows proxy settings to be bypassed using IPv6 zone identifiers in target addresses.
  6. Verify on each affected host that SUSE bug references bsc#1236515, bsc#1238680, bsc#1266556 and bsc#1279126 are resolved by confirming the installed package build string reads 0.26.0-bp160.1.1, and rebuild any locally compiled blackbox_exporter binaries against the updated Go modules.

Source

Code Red Cyber / VTA – coderedcyber.ai