This update for agama-web-ui fixes the following issues
- CVE-2025-7339: on-headers: incorrect array handling may lead to HTTP response header manipulation (bsc#1246678).
- CVE-2026-9277: shell-quote: improper escaping of newlines in object .op values by quote() can lead to shell command
injection (bsc#1266256).
- CVE-2026-42041: axios: authentication bypass via validateStatus prototype pollution gadget due to suppression of HTTP
error (bsc#1264160).
- CVE-2026-42264: axios: prototype pollution read-side gadgets in HTTP adapter can lead to credential injection and
request h (bsc#1264802).
Changes for agama-web-ui:
- Update other dependencies reported by "npm audit".
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-901=1
- openSUSE Leap 16.0:
agama-web-ui-17+612.d8bf69336-160000.11.1
* bsc#1246678
* bsc#1264160
* bsc#1264802
* bsc#1266256
References:
* https://www.suse.com/security/cve/CVE-2025-7339.html
* https://www.suse.com/security/cve/CVE-2026-42041.html
* https://www.suse.com/security/cve/CVE-2026-42264.html
* https://www.suse.com/security/cve/CVE-2026-9277.html
Get the latest Linux and open source security news straight to your inbox.