Update Info

openSUSE-2026-280


Security update for go-sendxmpp


Type: security
Severity: important
Issued: 2026-08-11
Description:
This update for go-sendxmpp fixes the following issues:

- Update to 0.17.0:
  * Add --ox-transfer-private-key to transfer the encrypted private key to PEP
    to transfer it to other devices (requires go-xmpp >= v0.3.7).
  * Add --ox-receive-private-key to receive the encrypted private key from PEP.
  * Add config option no_root_warning.
  * Add config option no_legacy_pgp_warning.
  * Also disable legacy PGP when running as root (Ox was already disabled).
  * Disable pinning for not using PLAIN when running as root.
  * Add config option ox_trust_mode with settings blind and tofu.
  * Due to new tofu trust mode for Ox, only one public key per contact is accepted for easier ID handling.
  * Ox: Check that fingerprint of received key equals the advertised one.
  * CVE-2026-39821: Failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (boo#1266617): Bump net to 0.57.0


              

Packages


  • go-sendxmpp-0.17.0-bp157.2.12.1