<div class="container">
    <h1>Security update for aws-iam-authenticator</h1>

    <table class="table table-striped table-bordered">
        <tbody>
        <tr>
            <th>Announcement ID:</th>
            <td>SUSE-SU-2026:2643-1</td>
        </tr>
        <tr>
            <th>Release Date:</th>
            <td>2026-06-26T08:35:07Z</td>
        </tr>
        
        <tr>
            <th>Rating:</th>
            <td>critical</td>
        </tr>
        <tr>
            <th>References:</th>
            <td>
                <ul>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1200528">bsc#1200528</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1201395">bsc#1201395</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1227519">bsc#1227519</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1239947">bsc#1239947</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1249141">bsc#1249141</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1265842">bsc#1265842</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1266651">bsc#1266651</a>
                        </li>
                    
                    
                </ul>
            </td>
        </tr>
        
            <tr>
                <th>
                    Cross-References:
                </th>
                <td>
                    <ul>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2022-1996.html">CVE-2022-1996</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2022-2385.html">CVE-2022-2385</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2024-39689.html">CVE-2024-39689</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2025-47910.html">CVE-2025-47910</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-33814.html">CVE-2026-33814</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-39821.html">CVE-2026-39821</a>
                        </li>
                    
                    </ul>
                </td>
            </tr>
            <tr>
                <th>CVSS scores:</th>
                <td>
                    <ul class="list-group">
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2022-1996</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">9.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2022-1996</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">9.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2022-1996</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">9.3</span>
                                <span class="cvss-vector">CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2022-2385</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">8.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2022-2385</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">8.8</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2024-39689</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">3.7</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2024-39689</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2024-39689</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2025-47910</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">5.4</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2025-47910</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">5.4</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-33814</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-33814</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-33814</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-39821</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">9.1</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-39821</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.4</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-39821</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">9.6</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N</span>
                            </li>
                        
                    </ul>
                </td>
            </tr>
        
        <tr>
            <th>Affected Products:</th>
            <td>
                <ul class="list-group">
                    
                        <li class="list-group-item">Public Cloud Module 15-SP4</li>
                    
                        <li class="list-group-item">Public Cloud Module 15-SP5</li>
                    
                        <li class="list-group-item">Public Cloud Module 15-SP6</li>
                    
                        <li class="list-group-item">Public Cloud Module 15-SP7</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise High Performance Computing 15 SP4</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise High Performance Computing 15 SP5</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 15 SP4</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 15 SP5</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 15 SP6</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 15 SP7</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP4</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP5</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP6</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP7</li>
                    
                        <li class="list-group-item">SUSE Manager Proxy 4.3</li>
                    
                        <li class="list-group-item">SUSE Manager Retail Branch Server 4.3</li>
                    
                        <li class="list-group-item">SUSE Manager Server 4.3</li>
                    
                </ul>
            </td>
        </tr>
        </tbody>
    </table>

    <p>An update that solves six vulnerabilities and has one security fix can now be installed.</p>

    


    
        <h2>Description:</h2>
    
    <p>This update for aws-iam-authenticator fixes the following issues</p>
<ul>
<li>CVE-2022-1996: CORS bypass (bsc#1200528).</li>
<li>CVE-2022-2385: aws-iam-authenticator AccessKeyID validation bypass (bsc#1201395).</li>
<li>CVE-2024-39689: remove root certificates from <code>GLOBALTRUST</code> from the root store.</li>
<li>CVE-2025-47910: net/http: CrossOriginProtection bypass patterns are over-broad.</li>
<li>CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE
  (bsc#1265842).</li>
<li>CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation
  bypass and privilege escalation (bsc#1266651).</li>
</ul>
<p>Changes for aws-iam-authenticator:</p>
<ul>
<li>Update to version 0.7.18</li>
<li>Merge pull request (#1062) from CaidenBorrego/new-release</li>
<li>Creating new release for CVE mitigation</li>
<li>Merge pull request (#1057) from CaidenBorrego/caidenb-versionbump</li>
<li>Merge remote-tracking branch &#x27;upstream/master&#x27; into caidenb-versionbump</li>
<li>Bump x/net and x/sys to remediate CVEs (bsc#1266651, CVE-2026-39821)</li>
<li>Update to 0.7.17</li>
<li>Merge pull request #1051 from CaidenBorrego/caidenb-versionbump</li>
<li>bumping version from 0.7.16->0.7.17</li>
<li>Merge pull request #1047 from CaidenBorrego/caidenb-reservedprefix-fix</li>
<li>fix: honor reservedPrefixConfig for ConfigMap and CRD backends</li>
<li>Merge pull request #1046 from CaidenBorrego/caidenb-gorunner-bump</li>
<li>fix: reject malformed mapping ARN in userIDStrict mode for dynamic files</li>
<li>Update to 0.7.16</li>
<li>Merge pull request #1041 from ronaldngounou/rngounou/bump-go-1.26.3</li>
<li>Pin GitHub Actions to full-length commit SHAs</li>
<li>fix: bump go version to 1.26.3 for CVEs</li>
<li>from version 0.7.15</li>
<li>Merge pull request #1035 from Ganiredi/bump-version-0.7.15</li>
<li>Bump version to 0.7.15</li>
<li>Merge pull request #1030 from Ganiredi/1.36-k8s-deps</li>
<li>1.36.0 dependency update</li>
<li>from version 0.7.14</li>
<li>Merge pull request #1029 from CaidenBorrego/caidenb-gorunner-bump</li>
<li>Bump version to 0.7.14</li>
<li>Bumping gorunner image tag in Dockerfile for CVE mitigation</li>
<li>from version 0.7.13</li>
<li>Merge pull request #1020 from dheeraj-coding/master</li>
<li>feat: add manual dispatch function for create-release.yml</li>
<li>Merge pull request #1019 from dheeraj-coding/master</li>
<li>fix: create-release workflow failures</li>
<li>Merge pull request #1017 from Ganiredi/1.36-k8s-deps</li>
<li>Merge pull request #1018 from dheeraj-coding/master</li>
<li>fix: build failure due to stale gcb image by updating to latest</li>
<li>Release 0.7.13</li>
<li>Merge pull request #1016 from Ganiredi/1.36-k8s-deps</li>
<li>Merge branch &#x27;master&#x27; into 1.36-k8s-deps</li>
<li>Merge pull request #1013 from kubernetes-sigs/dependabot/go_modules/misc-dependencies-be00ae3611</li>
<li>1.36.rc release</li>
<li>Merge pull request #1015 from dheeraj-coding/master</li>
<li>fix: bump go version 1.26.2 for CVEs</li>
<li>chore(deps): Bump the misc-dependencies group across 3 directories with 6 updates
 (bsc#1265842, CVE-2026-33814)</li>
<li>Merge pull request #1011 from kubernetes-sigs/dependabot/go_modules/observability-dependencies-9e34dd3c34</li>
<li>Merge pull request #1009 from kubernetes-sigs/dependabot/go_modules/misc-dependencies-b5e1eeb2d5</li>
<li>Merge pull request #1004 from bryantbiggs/chore/fix-goreleaser-deprecations</li>
<li>Merge pull request #1010 from kubernetes-sigs/dependabot/go_modules/aws-dependencies-7118f1d525</li>
<li>chore(deps): Bump the observability-dependencies group across 2 directories with 2 updates</li>
<li>chore(deps): Bump the aws-dependencies group across 2 directories with 6 updates</li>
<li>chore(deps): Bump the misc-dependencies group across 3 directories with 2 updates</li>
<li>Merge pull request #1008 from kubernetes-sigs/dependabot/go_modules/aws-dependencies-3ce7b5fcac</li>
<li>chore(deps): Bump the aws-dependencies group across 2 directories with 12 updates</li>
<li>Merge pull request #1006 from kubernetes-sigs/dependabot/go_modules/k8s-dependencies-09346e948b</li>
<li>chore(deps): Bump the k8s-dependencies group across 3 directories with 8 updates</li>
<li>Merge pull request #1005 from kubernetes-sigs/dependabot/go_modules/aws-dependencies-508cd0fd8e</li>
<li>chore(deps): Bump the aws-dependencies group across 2 directories with 15 updates</li>
<li>fix: update Makefile goreleaser target for v2 compatibility</li>
<li>fix: resolve goreleaser v2 deprecations</li>
<li>Update to version 0.7.12</li>
<li>Update OWNERS in reviewers and approvers list</li>
<li>Release 0.7.12</li>
<li>ci: add verify job to catch unrun gofmt and go mod tidy</li>
<li>chore(lint): harden linter config and fix coverage gaps</li>
<li>fix(lint): add revive and unparam linters with full compliance</li>
<li>ci: add unit test job, expand golangci config, add make update/verify</li>
<li>docs(e2e): fix Go version, remove non-existent make target, fix typo</li>
<li>docs(release): remove stale ECR image update instructions and fix asset version placeholders</li>
<li>fix: address code review findings in repo cleanup branch</li>
<li>docs: rewrite development.md as a practical local dev guide</li>
<li>chore: repo cleanup, developer experience improvements</li>
<li>chore: reduce binary size by 59% (80 MB -> 33 MB)</li>
<li>fix(lint): replace deprecated NewSimpleClientset and fix embedded field selector</li>
<li>fix(tests): address code review findings in integration test framework</li>
<li>fix(tests): address post-refactor issues and add go workspace</li>
<li>refactor(tests): remove k8s.io/kubernetes dependency from test modules</li>
<li>chore: update all dependencies to latest versions</li>
<li>Set GOWORK=off to make building with vendored dependencies work</li>
<li>Update to version 0.7.11</li>
<li>Merge pull request #988 from dstdfx/bump-version</li>
<li>Bump version to 0.7.11</li>
<li>Merge pull request #985 from dstdfx/bump-go-version-1.25.7</li>
<li>Update go.mod for e2e/int tests</li>
<li>Update go.mod</li>
<li>Merge pull request #986 from ShiriNmi1520/master</li>
<li>Clarify README "Run the server" deployment instructions</li>
<li>Bump go to 1.25.7</li>
<li>Merge pull request #983 from eks-distro-pr-bot/eks-distro-pr-bot/go-version-bumps</li>
<li>Creating PR to update Go version to 1.25.6</li>
<li>Update to version 0.7.10:</li>
<li>1.35.0 dependency update</li>
<li>Creating PR to update Go version to 1.25.5</li>
<li>chore(deps): Bump the observability-dependencies group across 2 directories with 1 update</li>
<li>chore(deps): Bump the misc-dependencies group across 3 directories with 13 updates</li>
<li>chore(deps): Bump the observability-dependencies group across 1 directory with 2 updates</li>
<li>chore(deps): Bump the misc-dependencies group across 3 directories with 27 updates</li>
<li>chore(deps): Bump the aws-dependencies group across 2 directories with 11 updates</li>
<li>chore(deps): Bump the misc-dependencies group across 2 directories with 17 updates</li>
<li>Update to version 0.7.9</li>
<li>Creating PR to update Go version to 1.25.4</li>
<li>chore(deps): Bump the aws-dependencies group across 2 directories with 13 updates</li>
<li>chore(deps): Bump golangci/golangci-lint-action in the actions group</li>
<li>chore(deps): Bump the observability-dependencies group across 3 directories with 2 updates</li>
<li>chore(deps): Bump sigs.k8s.io/apiserver-network-proxy/konnectivity-client</li>
<li>chore(deps): Bump the aws-dependencies group across 2 directories with 14 updates</li>
<li>bump golang version to 1.25.3</li>
<li>Creating PR to update Go version to 1.25.3</li>
<li>chore(deps): Bump github.com/onsi/ginkgo/v2</li>
<li>chore(deps): Bump the observability-dependencies group across 3 directories with 1 update</li>
<li>chore(deps): Bump the misc-dependencies group across 3 directories with 11 updates</li>
<li>chore(deps): Bump the misc-dependencies group across 3 directories with 5 updates</li>
<li>chore(deps): Bump the aws-dependencies group across 2 directories with 3 updates</li>
<li>Update to version 0.7.8</li>
<li>chore: Bump indirect Kubernetes dependencies to latest</li>
<li>chore: Bump Kubernetes dependencies to latest</li>
<li>Bump the misc-dependencies group across 3 directories with 18 updates</li>
<li>Bump the aws-dependencies group across 2 directories with 11 updates</li>
<li>Fix CVE-2025-47910</li>
<li>Bump go.opentelemetry.io/auto/sdk</li>
<li>Bump the aws-dependencies group across 2 directories with 1 update</li>
<li>Bump the misc-dependencies group across 3 directories with 10 updates</li>
<li>from version 0.7.7</li>
<li>add support for aws-eusc partition</li>
<li>chore: Commit changes from <code>make codegen</code></li>
<li>fix: Use <code>.go-version</code> for the go version</li>
<li>feat: Add <code>golanglint-ci</code> pull request review; resolve all findings</li>
<li>Add haoranleo as approver</li>
<li>Bump the observability-dependencies group across 3 directories with 3 updates</li>
<li>Bump actions/setup-go from 5 to 6 in the actions group</li>
<li>Bump the misc-dependencies group across 3 directories with 8 updates</li>
<li>Bump github.com/coreos/go-oidc</li>
<li>Bump the observability-dependencies group across 3 directories with 12 updates</li>
<li>from version 0.7.6</li>
<li>feat: Update go version to <code>1.25</code>; update dependencies to latest
 to patch reported vulnerabilities</li>
<li>Force TCP URLs for etcd compatibility</li>
<li>Update go dependencies with 1.34.0</li>
<li>Bump the k8s-dependencies group across 3 directories with 8 updates</li>
<li>Bump the k8s-dependencies group across 3 directories with 1 update</li>
<li>Bump actions/checkout from 4 to 5 in the actions group</li>
<li>Bump the aws-dependencies group across 2 directories with 13 updates</li>
<li>from version 0.7.5</li>
<li>migrate hostname verification to sdk go v2</li>
<li>from version 0.7.4</li>
<li>chore: Move observability dependencies to separate dependabot update group</li>
<li>Bump the aws-dependencies group across 2 directories with 12 updates</li>
<li>from version 0.7.3</li>
<li>update Approvers/reviewers</li>
<li>update go version to 1.24.4</li>
<li>added logs for global region fallback</li>
<li>added global region fallback to imds</li>
<li>Bump sigs.k8s.io/apiserver-network-proxy/konnectivity-client</li>
<li>bumps kops and k8s versions, replaced node label "master" with "control-plane"</li>
<li>added imds logic back in, with EC2_METADATA enabled by default</li>
<li>removed headersourceacct from ststest, return err if no region cfg</li>
<li>added context chaining, cleanup</li>
<li>add context chaining, client config fixes</li>
<li>Move non problematic cache logs into debug</li>
<li>Rename log-level to log-verbosity, remove AutomaticEnv</li>
<li>lint fixes</li>
<li>get region from imds if not in config</li>
<li>added go.sum entries for tests/integration, fixed imds nil pointer dereference</li>
<li>Revert "Bump sigs.k8s.io/apiserver-network-proxy/konnectivity-client"</li>
<li>added some context chaining, fixed region config in GetWithOptions</li>
<li>updated arn, deleted v1-v2 creds converter</li>
<li>updated pkg/token to v2</li>
<li>updated pkg/filecache</li>
<li>updated arn in pkg/server to use v2</li>
<li>updated pkg/server to use v2</li>
<li>upgraded ec2provider</li>
<li>Bump the misc-dependencies group across 3 directories with 5 updates</li>
<li>Bump the misc-dependencies group across 3 directories with 6 updates</li>
<li>Bump the misc-dependencies group across 3 directories with 9 updates</li>
<li>Use logrus for filecache logs</li>
<li>Add quiet mode (cache only)</li>
<li>from version 0.7.2</li>
<li>Bump the misc-dependencies group across 3 directories with 43 updates</li>
<li>Bump the k8s-dependencies group across 3 directories with 2 updates</li>
<li>from version 0.7.1</li>
<li>Revert "Add 2 more tag validation checks"</li>
<li>Update the gorunner to v0.18.0-eks-1-32-latest</li>
<li>update the go version to 1.24.2</li>
<li>adding yue9944882 to owner</li>
<li>adds http2 support</li>
<li>Bump the aws-dependencies group across 2 directories with 3 updates</li>
<li>Update configmap.go</li>
<li>release authenticator from mainline with 0.7.0</li>
<li>Bump goreleaser/goreleaser-action from 5 to 6 in the actions group</li>
<li>Bump the misc-dependencies group across 3 directories with 41 updates</li>
<li>Remove no-op err assignment</li>
<li>Fix credential expirability check</li>
<li>chore: Update golan x package transitive dependencies</li>
<li>fix: Correct codgen script due to deprecated script removal</li>
<li>Update configmap test per 1.32.0 change in client-go</li>
<li>Update upstream dependencies to v1.32.0</li>
<li>chore: Update to go <code>1.23.4</code></li>
<li>deps: Update <code>golang.org/x/crypto</code> library to remediate high CVE</li>
<li>chore: Add dependabot configuration to automatically check for package updates weekly</li>
<li>handle scenario when the file is created but doesn&#x27;t have content</li>
<li>update code and add tests</li>
<li>remove nnmin-aws from approver list</li>
<li>add kmala to the owners list</li>
<li>update metrics dimention to stsregion</li>
<li>add default timeout for http client</li>
<li>log sts host instead of global/regional</li>
<li>update log</li>
<li>remove typo and log line</li>
<li>remove typo</li>
<li>Bump test go versions</li>
<li>add logs and metrics dimentions to find sts call success/failures on global/regional endpoints</li>
<li>Bump go minor version</li>
<li>Update aws-iam-authenticator installation command</li>
<li>use protobuf content type instead of json for k8s client</li>
<li>Update RELEASE.md</li>
<li>Bump go-restful in e2e and integration tests</li>
<li>Bump go-restful</li>
<li>Remove outdated changelog artifacts</li>
<li>Bump deploy/example.yaml version</li>
<li>Update filecache to use AWS SDK Go V2 with wrappers</li>
<li>Refactored token filecache</li>
<li>Fix x-amz-expires header value</li>
<li>Remove parameterized AWS session from token.go</li>
<li>Parse source account from sourceARN</li>
<li>Add sourceArn to sts through headers</li>
<li>Add configurable Now time for signature generation</li>
<li>cleanup to use composite literals</li>
<li>update to sig.k8s.io namespace</li>
<li>retain original field</li>
<li>update the image to latest to fix CVE-2024-39689</li>
<li>add a namespaced field</li>
<li>Update upstream dependencies to v1.31.0</li>
<li>update the go version to 1.22.5</li>
<li>Add unit test</li>
<li>skip service validation to get the default regions endpoint</li>
<li>fix: Run <code>go mod tidy</code> to fix <code>go.sum</code> files</li>
<li>fix: Update goreleaser workflow to fix warnings and artifact generation</li>
<li>update aws go sdk to 1.54.6</li>
<li>chore: Remove emeritus reviewers from <code>SECURITY_CONTACTS</code></li>
<li>fix: Add random string to e2e test role to avoid pipeline run conflicts</li>
<li>fix: Run <code>go mod tidy</code> from <code>tests/integration</code> directory</li>
<li>chore: Update CLI dependencies <code>cobra</code> and <code>viper</code></li>
<li>updating google.golang.org/grpc/otelgrpc to v0.47.0</li>
<li>chore: Update CI action versions, remove <code>push</code> trigger</li>
<li>chore: Align go versions and remove unused files</li>
<li>updating k8s client libraries and go version</li>
<li>adding new approvers - nnmin-aws</li>
<li>Bump go version to 1.21.8</li>
<li>Bump github.com/golang/protobuf v1.5.4, google.golang.org/protobuf v1.33.0</li>
<li>chore: Re-update to latest patch version of K8s packages</li>
<li>fix time formatting</li>
<li>refactor structs for dynamic file load</li>
<li>add support for adoption rate metrics for cam</li>
<li>add support for e2e latency for dynamic mode</li>
<li>Switch to GOTOOLCHAIN env setting from gimme</li>
<li>Switch back to use go-version from go-image-tag</li>
<li>Switch to use go-image-tag from go-version</li>
<li>Repo controlled build go version</li>
<li>chore: Re-update and align</li>
<li>fix semantic error</li>
<li>feat: Re-update K8s packages to latest release</li>
<li>fix: Use <code>SIGDescribe</code></li>
<li>fix: Use <code>framework.WithDisruptive()</code></li>
<li>fix: [Disruptive] in plain text is deprecated and must be added through WithDisruptive instead</li>
<li>chore: Update dependencies for <code>e2e</code> tests</li>
<li>fix: Add context to <code>StartTestServer</code></li>
<li>fix: Align integration test <code>replace</code> versions in <code>go.mod</code></li>
<li>fix: Fix codegen and update <code>replace</code> test integration dependencies</li>
<li>fix: Integration test dependencies run <code>go mod tidy</code></li>
<li>fix: Downgrade <code>k8s.io/sample-controller</code> which requires updating context handling</li>
<li>chore: Update app K8s dependencies</li>
<li>adding nnmin-aws into reviewers</li>
<li>Replace deprecated <code>ioutil</code> package</li>
<li>fix base image to use latest</li>
<li>minor fix the IAM user arn verification</li>
<li>Fix role ARN comparison for user ID strict check (#669)</li>
<li>Check ARN for user ID strict check (#660)</li>
<li>Update go to 1.21.5</li>
<li>Change s3 bucket for e2e tests, current default exists somewhere (#652)</li>
<li>Bump minimum Go version to 1.25 in BuildRequires</li>
<li>Update to version 0.6.31</li>
<li>from version 0.6.30</li>
<li>Small fixes missed during cherrypicking</li>
<li>Cherry-picked file changes from commit
 https://github.com/kubernetes-sigs/aws-iam-authenticator/pull/554/commits</li>
<li>Simplify featuregate flag parsing for SSORoleMatch</li>
<li>Support un-canonicalized ARNs in filemapper</li>
<li>Add SSO Role suffix support (#416)</li>
<li>Chore: Update golang x package transitive dependencies</li>
<li>Add -buildmode=pie to go build command line (bsc#1239947)</li>
<li>Update to version 0.6.29</li>
<li>from version 0.6.28</li>
<li>Update owners list to sync master branch</li>
<li>Lpdate log</li>
<li>Add logs and metrics dimentions to find sts call
 success/failures on global/regional endpoints</li>
<li>Return 429 for STS throttling</li>
<li>Update to 0.6.27</li>
<li>from version 0.6.26</li>
<li>from version 0.6.25</li>
<li>from version 0.6.24</li>
<li>Update the image to latest to fix CVE-2024-3968</li>
<li>from version 0.6.23</li>
<li>Update to version 0.6.22</li>
<li>Update to version 0.6.21</li>
<li>from version 0.6.20</li>
<li>Merge pull request #713 from jaidevmane/updating-otelgrpc-to-v0.51.0</li>
<li>Merge pull request #709 from bryantbiggs/chore/update-ci-versions</li>
<li>Merge pull request #708 from jaidevmane/updating-deps</li>
<li>Merge pull request #707 from jaidevmane/adding-new-approvers</li>
<li>Merge pull request #687 from bryantbiggs/chore/update-app-k8s-dependencies</li>
<li>from version 0.6.19</li>
<li>Bump github.com/golang/protobuf v1.5.4,
 google.golang.org/protobuf v1.33.0</li>
<li>from version 0.6.18</li>
<li>from version 0.6.17</li>
<li>Fix base image to use latest and release v0.6.17</li>
<li>from version 0.6.16</li>
<li>from version 0.6.15</li>
<li>Fix role ARN comparison for user ID strict check (#669) (#671)</li>
<li>Bump minimum Go version to 1.22 in BuildRequires</li>
<li>Update to version 0.6.14</li>
<li>Check ARN for user ID strict check (#660) (#664)</li>
<li>Update go to 1.21.5 (#663)</li>
<li>Update go to 1.21.4 (#648) (#659)</li>
<li>Update to version 0.6.13</li>
<li>Cherry-pick: Fix federated user ID parsing #644 (#654)</li>
<li>Fix issue 606: use latest version of aws-sdk-go (#650)</li>
<li>Change s3 bucket for e2e tests, current default exists somewhere (#653)</li>
<li>from version 0.6.12</li>
<li>Avoid parsing single quote empty inputs</li>
<li>Avoid parsing known empty inputs</li>
<li>Update to version 0.6.11</li>
<li>Optimize only rebuild mapper when the actual backend modes change</li>
<li>Add int test for dynamic backend mode</li>
<li>Add DynamicBackendMode</li>
<li>Allow running create release from Github UI</li>
<li>Update to version 0.6.10</li>
<li>Update go.sum</li>
<li>Only replace x/net</li>
<li>Add build-all-images make target</li>
<li>Enable cross-compilation in Dockerfile</li>
<li>from version 0.6.9</li>
<li>Add DynamicFileError Metric</li>
<li>from version 0.6.8</li>
<li>Add comments explicitly on what we need to do later</li>
<li>Shutdown gracefully and avoid the extra thread
 leak checks that EtcdMain barfs on</li>
<li>Switch to newer ginkgo v2</li>
<li>Bump dependencies and go version (in go.mod) (bsc#1200528, CVE-2022-1996)</li>
<li>from version 0.6.7</li>
<li>(no changes)</li>
<li>from version 0.6.6</li>
<li>Add Username Prefix Enforce for DynamicFile mode</li>
<li>from version 0.6.5</li>
<li>Update the aws sdk go version to latest</li>
<li>Update base image in Docker file</li>
<li>from version 0.6.4</li>
<li>Loop up RoleMapping with UserId in dynamocfile mode</li>
<li>Install kind if it doesn&#x27;t exist to _output</li>
<li>Update server_test for expose principal ID in audit log</li>
<li>Expose Principal Id to audit log</li>
<li>Migrate away from google.com gcp project k8s-testimages</li>
<li>Build s390x/ppc64le binaries</li>
<li>Add default instance region in sts hostname</li>
<li>from version 0.6.3</li>
<li>Bump aws sdk go to v1.44.145</li>
<li>Update Dockerfile to pull from https://gallery.ecr.aws/ \
 eks-distro-build-tooling/golang to avoid reaching pull
 rate limit from docker.io</li>
<li>Add go mod for E2E</li>
<li>Add install kind into e2e script</li>
<li>Move e2e test from start dev script + minor fix for run.sh</li>
<li>Add end to end test for mountfile mode in kind Update Makefile
 to support run e2e from either kind or kops.</li>
<li>Add end to end test for dynamicfile backend</li>
<li>Update to version 0.6.2</li>
<li>Add automatic release creation</li>
<li>Add tag workflow to release-0.6 branch</li>
<li>Remove dependency from PR #416</li>
<li>Revert "Add SSO Role suffix support (#416)</li>
<li>from version 0.6.1</li>
<li>Test release tagging</li>
<li>Fix file permissions</li>
<li>Tag release on update to version.txt</li>
<li>Update Dockerfile to pull from
 https://gallery.ecr.aws/eks-distro-build-tooling/golang
 to avoid reaching pull rate limit from docker.io</li>
<li>Added Issue and PR templates (#517)</li>
<li>Update Dockerfile to use Golang as builder</li>
<li>from version 0.6.0</li>
<li>Print CommitID too on startup</li>
<li>Print version on startup</li>
<li>Add new backend mode DYNAMICFILE</li>
<li>Update go.mod and go.sum for tests/integrations</li>
<li>Replace tabs with spaces in go.mod</li>
<li>Bump aws sdk go to v1.44.107</li>
<li>Minor fix on the script to solve permission
 denied issue when run make start-dev</li>
<li>Working E2E tests in prow</li>
<li>Non-blocking E2E tests</li>
<li>Add e2e recipe to Makefile</li>
<li>Basic E2E testing for authenticator</li>
<li>Initialize metrics in NewVerifier() if needed</li>
<li>Added ConfiguredInitDirectories featuregate for init command</li>
<li>rm more v1alpha1 version</li>
<li>Bump 0.6 (#471)</li>
<li>Bump version in Makefile</li>
<li>Add query parameter validation for multiple parameters</li>
<li>Replace deprecated seccomp annotation with seccompProfile.</li>
<li>Replace deprecated critical pod annotation with priorityClassName.</li>
<li>Whitespace consistency fixes.</li>
<li>Use rbac.authorization.k8s.io/v1 instead of v1beta1 in example manifest.</li>
<li>Lowercase the ARN keys</li>
<li>Remove vendor directory</li>
<li>linux/amd64 only for image target</li>
<li>Don&#x27;t push on image target</li>
<li>from version 0.5.16</li>
<li>Shutdown gracefully and avoid the extra thread leak
 checks that EtcdMain barfs on</li>
<li>Bump dependencies and go version (in go.mod)</li>
<li>from version 0.5.15</li>
<li>from version 0.5.14</li>
<li>from version 0.5.13</li>
<li>from version 0.5.12</li>
<li>Fix Makefile on branch release-0.5 (#520)</li>
<li>rm more v1alpha1 version (#516)</li>
<li>from version 0.5.11</li>
<li>Add end to end test for mountfile mode in kind Update
 Makefile to support run e2e from either kind or kops.</li>
<li>Update to version 0.5.10</li>
<li>Automated cherry pick of #491: Bump aws sdk go to v1.44.107 (#493)</li>
<li>Remove vendor from release-0.5 (#498)</li>
<li>Update to version 0.5.9</li>
<li>Add query parameter validation for multiple parameters (#469)
 (bsc#1201395, CVE-2022-2385)</li>
<li>from version 0.5.8</li>
<li>Revert use of upstream yaml parsing (#455)</li>
<li>from version 0.5.7</li>
<li>Remove duplicate InitMetrics by @jngo2 in (#448)</li>
<li>Fixes a crash when executing authenticator in server mode</li>
<li>from version 0.5.6</li>
<li>Bump AWS SDK to v1.43.28 (#445)</li>
<li>Use the apiversion from KUBERNETES_EXEC_INFO (#439)</li>
<li>Bump promptui module to v0.9.0 (#437)</li>
<li>from version 0.5.5</li>
<li>Use full package name for goreleaser version (#433)</li>
<li>Add sts error metric (#430)</li>
<li>Emit metric for EC2 describeInstance calls (#428)</li>
<li>Rename configmap_watch_failures to configmap_watch_failures_total (#432)</li>
<li>Simplify goreleaser Dockerfiles (#431)</li>
<li>Don&#x27;t pass metrics around (#423)</li>
<li>from version 0.5.4</li>
<li>Embed go-runner into the image (#426)</li>
<li>Bump Go to 1.17 in Travis (#414)</li>
<li>Build multi-arch images (#417)</li>
<li>Add kind-based development environment (#422</li>
<li>Add jaypipes to approvers/reviewers (#407</li>
<li>Fix deps (#396</li>
<li>Fix panic when cache file can&#x27;t be Stat-ed (#410</li>
<li>Fix missing status definition in v1 CRD (#411)</li>
<li>Use ./hack/install-etcd.sh (#405</li>
<li>Run integration tests with per-test role (#402</li>
<li>Add a counter for API server watch failures (#400)</li>
<li>Upgrade CRD manifest to v1 (#397</li>
<li>Move inactives to emeritus_approvers and add active users (#399)</li>
<li>Fix tests add vendor (#398)</li>
<li>Integration test framework (#395)</li>
<li>Add cloudbuild & improvements (#394)</li>
<li>Fix typo (#390)</li>
<li>Add user/role subcommands (#381)</li>
<li>goreleaser: bump release to 0.164.0 and fix config deprecations (#371)</li>
<li>Run go mod vendor (#388)</li>
<li>doc: fix typo in RELEASE.md (#376)</li>
<li>[pkg/token]: Update credential API version (#386)</li>
<li>Enrich Audit Logs with additional AWS Identity details
 (via audit logs&#x27; "extra" map) (#372)</li>
<li>Enable vendoring for Go module dependencies</li>
</ul>



    

    <h2>Patch Instructions:</h2>
    <p>
        To install this SUSE  update use the SUSE recommended
        installation methods like YaST online_update or "zypper patch".<br/>

        Alternatively you can run the command listed for your product:
    </p>
    <ul class="list-group">
        
            <li class="list-group-item">
                Public Cloud Module 15-SP7
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-2643=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                Public Cloud Module 15-SP5
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-2643=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                Public Cloud Module 15-SP6
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-2643=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                Public Cloud Module 15-SP4
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-2643=1</code>
                    
                    
                
            </li>
        
    </ul>

    <h2>Package List:</h2>
    <ul>
        
            
                <li>
                    Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64)
                    <ul>
                        
                            <li>aws-iam-authenticator-0.7.18-150000.1.17.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64)
                    <ul>
                        
                            <li>aws-iam-authenticator-0.7.18-150000.1.17.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64)
                    <ul>
                        
                            <li>aws-iam-authenticator-0.7.18-150000.1.17.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64)
                    <ul>
                        
                            <li>aws-iam-authenticator-0.7.18-150000.1.17.1</li>
                        
                    </ul>
                </li>
            
        
    </ul>

    
        <h2>References:</h2>
        <ul>
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2022-1996.html">https://www.suse.com/security/cve/CVE-2022-1996.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2022-2385.html">https://www.suse.com/security/cve/CVE-2022-2385.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2024-39689.html">https://www.suse.com/security/cve/CVE-2024-39689.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2025-47910.html">https://www.suse.com/security/cve/CVE-2025-47910.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-33814.html">https://www.suse.com/security/cve/CVE-2026-33814.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-39821.html">https://www.suse.com/security/cve/CVE-2026-39821.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1200528">https://bugzilla.suse.com/show_bug.cgi?id=1200528</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1201395">https://bugzilla.suse.com/show_bug.cgi?id=1201395</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1227519">https://bugzilla.suse.com/show_bug.cgi?id=1227519</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1239947">https://bugzilla.suse.com/show_bug.cgi?id=1239947</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1249141">https://bugzilla.suse.com/show_bug.cgi?id=1249141</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1265842">https://bugzilla.suse.com/show_bug.cgi?id=1265842</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1266651">https://bugzilla.suse.com/show_bug.cgi?id=1266651</a>
                    </li>
                
            
        </ul>
    
</div>