PT-2026-83612 · Opensuse · Bugwarden
Published
2026-08-20
·
Updated
2026-08-20
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This update for bugwarden fixes the following issues:
Changes in bugwarden:
- Update to 0.5.0:
- Let the environment set allowed hosts and the auth header
- Require a bearer token on the HTTP transport
- Export audit records and diagnostics to an OTLP collector
- Handle SIGTERM so container stop is graceful
- Refuse unparsable allowed-hosts at startup
- Normalize tool schemas for Gemini/Vertex clients, and recurse portable schema into all draft-2020-12 positions
-
Vendored h2 bumped to 0.4.16 for RUSTSEC-2026-0258 / GHSA-q83h-524g-xf6h (h2 unbounded empty DATA frames lead to denial of service)
-
Ship the worked OpenTelemetry collector example as documentation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bugwarden