Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE Python Important Code Exec Information Disclosure Vuln 2026-2387-1

suse
Calendar Grey June 12, 2026
Dist Suse Esm H88
SUSE security update resolves six critical issues in Python requiring immediate action to prevent code execution and data leakage.
An update that solves six vulnerabilities and has one security fix can now be installed.

Summary

## This update for python fixes the following issues * CVE-2026-1703: files may be extracted outside the installation directory when installing and extracting maliciously crafted wheel archives (bsc#1257599). * CVE-2026-3219: pip doesn't reject concatenated ZIP (bsc#1262429). * CVE-2026-4786: Incomplete mitigation of %action expansion for command injection to webbrowser.open() (bsc#1262319). * CVE-2026-6019: BaseCookie.js_output() does not neutralize embedded characters (bsc#1262654). * CVE-2026-6100: arbitrary code execution or information disclosure via use- after-free in decompression modules (bsc#1262098). * CVE-2026-6357: pip self-update functionality can import newly installed modules after wheel installation (bsc#1263442). Changes for python:

References

* bsc#1257599

* bsc#1261652

* bsc#1262098

* bsc#1262319

* bsc#1262429

* bsc#1262654

* bsc#1263442

Cross-

* CVE-2026-1703

* CVE-2026-3219

* CVE-2026-4786

* CVE-2026-6019

* CVE-2026-6100

* CVE-2026-6357

CVSS scores:

* CVE-2026-1703 ( SUSE ): 2.1

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

* CVE-2026-1703 ( NVD ): 2.0

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2026-3219 ( SUSE ): 4.6

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2387-1
Release Date: 2026-06-12T13:57:54Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here