Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves two vulnerabilities can now be installed.. # Security update for python-starlette Announcement ID: SUSE-SU-2026:2470-1 Release Date: 2026-06-19T13:37:51Z Rating: important References: * bsc#1268517 * bsc#1268520 Cross-References: * CVE-2026-54282 * CVE-2026-54283 CVSS scores: * CVE-2026-54282 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-54282 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-54283 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-54283 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-starlette fixes the following issues * CVE-2026-54282: request path that lacks a leading forward slash can lead to request.url.hostname manipulation (bsc#1268520). * CVE-2026-54283: urlencoded request body with an oversized data can lead to a denial of service (bsc#1268517). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2470=1 ## Package List: * openSUSE Leap 15.6 (noarch) * python311-starlette-0.35.1-150600.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54282.html * https://www.suse.com/security/cve/CVE-2026-54283.html * https://bugzilla.suse.com/show_bug.cgi?id=1268517 * https://bugzilla.suse.com/show_bug.cgi?id=1268520 . An important security update for python-starlette on SUSE fixes critical issues, enabling safer operations.. SUSE python-starlette update, important security patches SUSE, request manipulation fix, denial of service vulnerability. . Severity: Important. LinuxSecurity.com Team
In httplib2, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts . Package : python-httplib2 Version : 0.9+dfsg-2+deb8u1 CVE ID : CVE-2020-11078 In httplib2, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping. For Debian 8 "Jessie", this problem has been fixed in version 0.9+dfsg-2+deb8u1. We recommend that you upgrade your python-httplib2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance the python-httplib2 library to mitigate risks associated with URI exploitation by malicious entities, potentially resulting in unauthorized API calls.. Debian Security Update, python-httplib2, Vulnerability Prevention. . LinuxSecurity.com Team
Andrey Labunets of Facebook discovered that cURL, an URL transfer library, fails to properly handle URLs with embedded end-of-line characters. An attacker able to make an application using libcurl to access a specially crafted URL via an HTTP proxy could use this flaw to . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3122-1
Get the latest Linux and open source security news straight to your inbox.