An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for cockpit-repos ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20251-1 Rating: important References: * bsc#1255425 * bsc#1257325 Cross-References: * CVE-2025-13465 * CVE-2025-64718 CVSS scores: * CVE-2025-13465 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2025-13465 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-64718 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2025-64718 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for cockpit-repos fixes the following issues: Update to version 4.7. Security issues fixed: - CVE-2025-13465: prototype pollution in the _.unset and _.omit functions can lead to deletion of methods from global (bsc#1257325). - CVE-2025-64718: js-yaml prototype pollution in merge (bsc#1255425). Other updates and bugfixes: - version update to 4.7 * Translation updates - version update to 4.6: * Translation updates * Dependency updates * Fix translations pot file not being update - version update to 4.5: * Dependency updates - version update to 4.4: * Translation updates * Dependency updates Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-296=1 Package List: - openSUSE Leap 16.0: cockpit-repos-4.7-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2025-13465.html *https://www.suse.com/security/cve/CVE-2025-64718.html . Security update for openSUSE cockpit-repos addresses critical issues related to prototype pollution and security risks.. openSUSE cockpit-repos security important prototype pollution. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.