Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

SUSE: Python Moderate Security Update CVE-2025-12084 2026:0133-1

suse
Calendar Grey January 16, 2026
Dist Suse Esm H88
Security update resolves three moderate issues in Python with detailed patch instructions for SUSE users.
An update that solves three vulnerabilities can now be installed.

Summary

## This update for python fixes the following issues: * CVE-2025-8291: check validity of the ZIP64 End of Central Directory (EOCD) in the 'zipfile' module (bsc#1251305). * CVE-2025-12084: prevent quadratic behavior in node ID cache clearing (bsc#1254997). * CVE-2025-13836: prevent reading an HTTP response from a server, if no read amount is specified, with using Content-Length per default as the length (bsc#1254400). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-133=1 ## Package List:

References

* bsc#1251305

* bsc#1254400

* bsc#1254997

Cross-

* CVE-2025-12084

* CVE-2025-13836

* CVE-2025-8291

CVSS scores:

* CVE-2025-12084 ( SUSE ): 6.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2025-12084 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

* CVE-2025-12084 ( NVD ): 6.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2025-12084 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2025-13836 ( SUSE ): 6.3

Announcement ID: SUSE-SU-2026:0133-1
Release Date: 2026-01-16T09:19:41Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here