Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

openSUSE Leap 16.0 agama-web-ui Important Security Patch SUSE-2026-21448-1

opensuse
Calendar Grey July 28, 2026
Scroller Opensuse
This update resolves 13 issues in agama-web-ui with potential DoS and security risks. Ensure you update for safety.
openSUSE released a security update for agama-web-ui addressing 13 vulnerabilities with 14 bug fixes, focusing on various issues related to data handling and security exploits.

Description

This update for agama-web-ui fixes the following issues:

- CVE-2025-7783: form-data: unsafe `Math.random()` function is used to select a boundary value for multipart

form-encoded data (bsc#1246822).

- CVE-2026-12143: form-data: CRLF injection via unescaped multipart field names and filenames (bsc#1272310).

- CVE-2026-13149: brace-expansion: `expand()` function exhibits exponential-time complexity when processing

non-expanding `{}` brace groups (bsc#1269927).

- CVE-2026-13311: shell-quote: quadratic complexity in `parse()` function when processing specially crafted strings

(bsc#1269359).

- CVE-2026-13676: fast-uri: host-based policy bypass due to failure to canonicalize Unicode/IDN hostnames for

HTTP-family URLs (bsc#1269595).

- CVE-2026-27601: underscore: DoS via stack overflow due to missing depth limits in `_.flatten` and `_.isEqual`

functions (bsc#1259169).

- CVE-2026-40181: react-router: open redirect to an external domain due to path values starting with `//` being

...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

agama-web-ui-17+673.b97ba64d6-160000.12.1

References

* bsc#1246822

* bsc#1259169

* bsc#1268851

* bsc#1269359

* bsc#1269514

* bsc#1269595

* bsc#1269927

* bsc#1272310

* bsc#1272311

* bsc#1272312

* bsc#1272313

* bsc#1272317

* bsc#1272318

* bsc#1272319

References:

* https://www.suse.com/security/cve/CVE-2025-7783.html

* https://www.suse.com/security/cve/CVE-2026-12143.html

* https://www.suse.com/security/cve/CVE-2026-13149.html

* https://www.suse.com/security/cve/CVE-2026-13311.html

* https://www.suse.com/security/cve/CVE-2026-13676.html

* https://www.suse.com/security/cve/CVE-2026-27601.html

* https://www.suse.com/security/cve/CVE-2026-40181.html

* https://www.suse.com/security/cve/CVE-2026-49356.html

* https://www.suse.com/security/cve/CVE-2026-53550.html

* https://www.suse.com/security/cve/CVE-2026-53632.html

* https://www.suse.com/security/cve/CVE-2026-54466.html

* https://www.suse.com/security/cve/CVE-2026-54490.html

* https://www.suse.com/security/cve/CVE-2026-55602.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21448-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.