CODERED VTA

openSUSE Updates Prometheus Alertmanager on Leap 16.0 to Fix Two Go Dependency Vulnerabilities

High
Matrix code on screen
Photo by Markus Spiske on Unsplash

openSUSE has issued advisory openSUSE-SU-2026:22027-1, rated important, for golang-github-prometheus-alertmanager on openSUSE Leap 16.0, covering two CVEs in bundled Go dependencies. The first is CVE-2026-2303, scored 5.4 by SUSE under CVSS 3.1, which was resolved by removing an indirect dependency on a vulnerable MongoDB driver (bsc#1269834). It ships alongside CVE-2026-39821, a validation bypass and privilege escalation issue scored 7.4 under CVSS 3.1 and 9.1 under CVSS 4.0, fixed by updating golang.org/x/net to version 0.57.0 (bsc#1266615). Any Leap 16.0 host running Alertmanager below the fixed build of 0.33.1-bp160.1.1 is in scope.

The advisory does not publish exploitation details for either issue, so no attack chain should be assumed beyond what the vendor states. What is documented is the dependency path: both flaws reach Alertmanager indirectly, one through the golang.org/x/net library that handles network and protocol parsing, and the other through a MongoDB driver pulled in as a transitive dependency rather than used directly by the application. The CVSS vectors give the clearest picture of reachability. CVE-2026-39821 is described as network-reachable with no privileges and no user interaction required, with high impact on confidentiality and integrity, while CVE-2026-2303 requires user interaction and carries only low confidentiality and availability impact. The same update also rolls the package forward through releases 0.29.0 to 0.33.1, which add Microsoft Teams adaptive cards, Google Chat and Mattermost notifiers, AWS Signature V4 support and distributed tracing, and fix dispatcher goroutine leaks and a silences snapshot bug.

Alertmanager sits in the monitoring tier, where it holds webhook endpoints, Slack and Jira tokens, SMTP settings and routing rules for an entire estate, so a validation bypass with privilege escalation characteristics in that tier is worth more to an attacker than its placement might suggest. Many deployments also expose the Alertmanager API internally for integrations, which widens the set of callers that can reach the vulnerable code paths. On current exploitation data, neither issue is being used against real targets: FIRST EPSS puts CVE-2026-39821 at a 0.7 percent probability of exploitation in the next 30 days and CVE-2026-2303 at 0.3 percent. The pattern that matters here is recurrence, with the same upstream Go libraries generating repeat advisories across distributions as each vendor rebuilds its own packages.

Attack Surface

Supply Chain (Third-party vendors), Server OS, Infrastructure

Tactics

Privilege Escalation, Initial Access, Defense Evasion

Techniques

  • T1068 – Exploitation for Privilege Escalation
  • T1195.001 – Compromise Software Supply Chain: Compromise Software Dependencies and Development Tools
  • T1190 – Exploit Public-Facing Application

SuperPRO's Threat Countermeasures Procedures

  1. Install the fixed package golang-github-prometheus-alertmanager-0.33.1-bp160.1.1 on openSUSE Leap 16.0 by running zypper in -t patch openSUSE-Leap-16.0-packagehub-655=1, or apply it through YaST online_update or zypper patch.
  2. Inventory every Leap 16.0 host carrying golang-github-prometheus-alertmanager with rpm -q golang-github-prometheus-alertmanager and treat any build below 0.33.1-bp160.1.1 as vulnerable to CVE-2026-39821 and CVE-2026-2303.
  3. Rebuild or repull any in-house Go binaries and container images that vendor golang.org/x/net, since CVE-2026-39821 is only closed at version 0.57.0 or later; verify with go list -m golang.org/x/net or govulncheck against each module.
  4. Confirm on each Leap 16.0 host that the vulnerable indirect MongoDB driver is gone by moving to golang-github-prometheus-alertmanager-0.33.1-bp160.1.1, the build in which that dependency was removed for CVE-2026-2303, and verify with zypper info golang-github-prometheus-alertmanager.
  5. Restrict the Alertmanager HTTP API and UI, typically on TCP/9093, and the cluster gossip port TCP/9094, to the Prometheus servers and management subnets that require them, rather than leaving them reachable across the flat internal network.
  6. Rotate notifier secrets held in alertmanager.yml for Slack, Microsoft Teams, Jira, Mattermost, PagerDuty and SMTP integrations on any host that was running an unpatched build and was reachable from untrusted networks.
  7. Validate the upgrade in a staging cluster first, because release 0.33.0 removes the –enable-feature=auto-gomaxprocs flag and 0.33.1 changes the silences snapshot format, which can break startup or downgrade compatibility with older peers.

Source

Code Red Cyber / VTA – coderedcyber.ai