An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for python-weasyprint ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0026-1 Rating: important References: #1256936 Cross-References: CVE-2025-68616 CVSS scores: CVE-2025-68616 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-weasyprint fixes the following issues: - CVE-2025-68616: Fixed a server-side request forgery in default fetcher (boo#1256936). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2026-26=1 Package List: - openSUSE Backports SLE-15-SP6 (noarch): python311-weasyprint-60.2-bp156.2.3.1 References: https://www.suse.com/security/cve/CVE-2025-68616.html https://bugzilla.suse.com/1256936 . Update fixes important vulnerability in python-weasyprint for openSUSE enhancing security. Immediate patching recommended.. openSUSE update, python-weasyprint security, server-side request forgery fix, importance rating, security patch process. . Severity: Important. LinuxSecurity.com Team
The container bci/nodejs was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3565-1 Container Tags : bci/node:18 , bci/node:18-11.25 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-11.25 , bci/nodejs:latest Container Release : 11.25 Severity : important Type : security References : 1216123 1216174 1216378 CVE-2023-44487 CVE-2023-45853 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4200-1 Released: Wed Oct 25 12:04:29 2023 Summary: Security update for nghttp2 Type: security Severity: important References: 1216123,1216174,CVE-2023-44487 This update for nghttp2 fixes the following issues: - CVE-2023-44487: Fixed HTTP/2 Rapid Reset attack. (bsc#1216174) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4215-1 Released: Thu Oct 26 12:19:25 2023 Summary: Security update for zlib Type: security Severity: moderate References: 1216378,CVE-2023-45853 This update for zlib fixes the following issues: - CVE-2023-45853: Fixed an integer overflow that would lead to a buffer overflow in the minizip subcomponent (bsc#1216378). The following package changes have been done: - libz1-1.2.13-150500.4.3.1 updated - libnghttp2-14-1.40.0-150200.12.1 updated - container:sles15-image-15.0.0-36.5.50 updated . SUSE Container Release for bci/python incorporates essential security fixes that mitigate significant vulnerabilities.. bci/nodejs, container security, patch management. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.