Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 538
Alerts This Week
Warning Icon 1 538

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 217 articles for you...
89

Fedora 44 tinyproxy Important HTTP Request Smuggling Fixes 2026-efbe094630

Backport upstream fixes for CVE-2026-54387 and CVE-2026-54388.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-efbe094630 2026-06-27 01:10:00.374896+00:00 -------------------------------------------------------------------------------- Name : tinyproxy Product : Fedora 44 Version : 1.11.2 Release : 8.fc44 URL : https://tinyproxy.github.io/ Summary : A small, efficient HTTP/SSL proxy daemon Description : tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a small network setting, where a larger proxy like Squid would either be too resource intensive, or a security risk. -------------------------------------------------------------------------------- Update Information: Backport upstream fixes for CVE-2026-54387 and CVE-2026-54388. -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 18 2026 Carl George - 1.11.2-8 - Backport upstream CVE fixes - Fixes CVE-2026-54387 - Fixes CVE-2026-54388 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2490299 - CVE-2026-54387 tinyproxy: HTTP Request Smuggling via CL/TE desynchronization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490299 [ 2 ] Bug #2490301 - CVE-2026-54388 tinyproxy: HTTP Request Smuggling via duplicate Content-Length headers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490301 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-efbe094630' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update tinyproxy for Fedora 44 addresses critical HTTP request smuggling issues with important fixes.. Fedora tinyproxy HTTP Proxy Security Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 26, 2026 Important Fedora
89

Fedora 43 tinyproxy Important HTTP Request Smuggling Fix 2026-77f1ca9c8f

Backport upstream fixes for CVE-2026-54387 and CVE-2026-54388.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-77f1ca9c8f 2026-06-27 00:54:50.049783+00:00 -------------------------------------------------------------------------------- Name : tinyproxy Product : Fedora 43 Version : 1.11.2 Release : 8.fc43 URL : https://tinyproxy.github.io/ Summary : A small, efficient HTTP/SSL proxy daemon Description : tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a small network setting, where a larger proxy like Squid would either be too resource intensive, or a security risk. -------------------------------------------------------------------------------- Update Information: Backport upstream fixes for CVE-2026-54387 and CVE-2026-54388. -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 18 2026 Carl George - 1.11.2-8 - Backport upstream CVE fixes - Fixes CVE-2026-54387 - Fixes CVE-2026-54388 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2490299 - CVE-2026-54387 tinyproxy: HTTP Request Smuggling via CL/TE desynchronization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490299 [ 2 ] Bug #2490301 - CVE-2026-54388 tinyproxy: HTTP Request Smuggling via duplicate Content-Length headers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490301 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-77f1ca9c8f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Important update for Fedora 43 to address security issues in tinyproxy with CVE-2026-54387 and CVE-2026-54388.. fedora tinyproxy cve fix proxy. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 26, 2026 Important Fedora
100

SUSE Linux Micro 6.0 libsoup Moderate HTTP Request Smuggling 22061-1

An update that solves one vulnerability can now be installed.. # Security update for libsoup Announcement ID: SUSE-SU-2026:22061-1 Release Date: 2026-06-05T15:20:34Z Rating: moderate References: * bsc#1257649 Cross-References: * CVE-2026-1801 CVSS scores: * CVE-2026-1801 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1801 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-1801 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-1801 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for libsoup fixes the following issue * CVE-2026-1801: HTTP Request Smuggling in soup_filter_input_stream_read_line() (bsc#1257649). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-743=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libsoup-3_0-0-3.4.2-16.1 * libsoup-debugsource-3.4.2-16.1 * libsoup-3_0-0-debuginfo-3.4.2-16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1801.html * https://bugzilla.suse.com/show_bug.cgi?id=1257649 . Discover the latest SUSE security advisory for libsoup addressing a moderate HTTP Request Smuggling issue.. SUSE Security Update, libsoup Security Patch, HTTP Request Smuggling, SUSE Linux Micro, CVE-2026-1801. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 12, 2026 moderate SuSE
172

Ubuntu 26.04 Netty Key Security Update for Request Smuggling Flaws

Several security issues were fixed in Netty.. ========================================================================== Ubuntu Security Notice USN-8401-1 June 08, 2026 netty vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Netty. Software Description: - netty: event-driven asynchronous network application framework Details: It was discovered that Netty's HTTP proxy handler did not properly validate headers when constructing CONNECT requests. An attacker could possibly use this issue to inject arbitrary HTTP headers into CONNECT requests. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42578) It was discovered that Netty's DNS codec did not properly enforce domain name constraints. An attacker could possibly use this issue to bypass domain name validation, or cause Netty to consume resources, leading to a denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42579) It was discovered that Netty did not correctly handle HTTP/1.0 requests containing both a Transfer-Encoding and Content-Length header. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks. (CVE-2026-42581) Violeta Georgieva discovered that Netty incorrectly paired responses with requests when handling informational HTTP responses. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks. (CVE-2026-42584) Violeta Georgieva discovered that Netty incorrectly parsed malformed Transfer-Encoding headers. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks. (CVE-2026-42585) It was discovered thatNetty's Redis encoder did not validate CRLF characters. An attacker could possibly use this issue to inject arbitrary Redis commands. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42586) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libnetty-java 1:4.1.48-16ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 24.04 LTS libnetty-java 1:4.1.48-9ubuntu0.1+esm3 Available with Ubuntu Pro Ubuntu 22.04 LTS libnetty-java 1:4.1.48-4+deb11u2ubuntu0.1+esm3 Available with Ubuntu Pro Ubuntu 20.04 LTS libnetty-java 1:4.1.45-1ubuntu0.1~esm6 Available with Ubuntu Pro Ubuntu 18.04 LTS libnetty-java 1:4.1.7-4ubuntu0.1+esm6 Available with Ubuntu Pro Ubuntu 16.04 LTS libnetty-java 1:4.0.34-1ubuntu0.1~esm4 Available with Ubuntu Pro Ubuntu 14.04 LTS libnetty-java 1:3.2.6.Final-2+deb8u2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8401-1 CVE-2026-42578, CVE-2026-42579, CVE-2026-42581, CVE-2026-42584, CVE-2026-42585, CVE-2026-42586 . Netty vulnerabilities in Ubuntu require updates to prevent request smuggling and denial of service attacks. Stay secure!. Ubuntu Netty security fix, request smuggling Ubuntu, Denial of Service Netty, security advisory update, arbitrary command injection. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 08, 2026 Important Ubuntu
172

Ubuntu Netty Critical HTTP Injection DoS Vulnerabilities USN-8401-1

Several security issues were fixed in Netty.. ========================================================================== Ubuntu Security Notice USN-8401-1 June 08, 2026 netty vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Netty. Software Description: - netty: event-driven asynchronous network application framework Details: It was discovered that Netty's HTTP proxy handler did not properly validate headers when constructing CONNECT requests. An attacker could possibly use this issue to inject arbitrary HTTP headers into CONNECT requests. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42578) It was discovered that Netty's DNS codec did not properly enforce domain name constraints. An attacker could possibly use this issue to bypass domain name validation, or cause Netty to consume resources, leading to a denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42579) It was discovered that Netty did not correctly handle HTTP/1.0 requests containing both a Transfer-Encoding and Content-Length header. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks. (CVE-2026-42581) Violeta Georgieva discovered that Netty incorrectly paired responses with requests when handling informational HTTP responses. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks. (CVE-2026-42584) Violeta Georgieva discovered that Netty incorrectly parsed malformed Transfer-Encoding headers. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks. (CVE-2026-42585) It was discovered thatNetty's Redis encoder did not validate CRLF characters. An attacker could possibly use this issue to inject arbitrary Redis commands. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42586) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libnetty-java 1:4.1.48-16ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 24.04 LTS libnetty-java 1:4.1.48-9ubuntu0.1+esm3 Available with Ubuntu Pro Ubuntu 22.04 LTS libnetty-java 1:4.1.48-4+deb11u2ubuntu0.1+esm3 Available with Ubuntu Pro Ubuntu 20.04 LTS libnetty-java 1:4.1.45-1ubuntu0.1~esm6 Available with Ubuntu Pro Ubuntu 18.04 LTS libnetty-java 1:4.1.7-4ubuntu0.1+esm6 Available with Ubuntu Pro Ubuntu 16.04 LTS libnetty-java 1:4.0.34-1ubuntu0.1~esm4 Available with Ubuntu Pro Ubuntu 14.04 LTS libnetty-java 1:3.2.6.Final-2+deb8u2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8401-1 CVE-2026-42578, CVE-2026-42579, CVE-2026-42581, CVE-2026-42584, CVE-2026-42585, CVE-2026-42586 . Multiple critical issues fixed in Netty for Ubuntu affecting various LTS releases, including HTTP injection and DoS risks.. Ubuntu security, Netty fixes, HTTP smuggling. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 08, 2026 Critical Ubuntu
197

Debian LTS python-aiohttp Advisory DLA-4613-1 Request Smuggling DoS

Several vulnerabilities have been found in aiohttp, an asynchronous HTTP client/server framework for asyncio and Python. CVE-2025-53643 Request smuggling vulnerability due to not parsing trailer sections of an HTTP request.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4613-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Daniel Leidert June 01, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : python-aiohttp Version : 3.7.4-1+deb11u2 CVE ID : CVE-2025-53643 CVE-2025-69224 CVE-2025-69225 CVE-2025-69226 CVE-2025-69227 CVE-2025-69228 CVE-2025-69229 CVE-2026-22815 CVE-2026-34513 CVE-2026-34514 CVE-2026-34516 CVE-2026-34517 CVE-2026-34518 CVE-2026-34519 CVE-2026-34520 CVE-2026-34525 Several vulnerabilities have been found in aiohttp, an asynchronous HTTP client/server framework for asyncio and Python. CVE-2025-53643 Request smuggling vulnerability due to not parsing trailer sections of an HTTP request. CVE-2025-69224 Possible request smuggling attack in the HTTP parser with the presence of non-ASCII characters. CVE-2025-69225 Parser logic which allows non-ASCII decimals to be present in the Range header. CVE-2025-69226 Path traversal vulnerability that allows an attacker to ascertain the existence of path components. CVE-2025-69227 When processing a POST body, an infinite loop can occur when assert statements are bypassed leading to a possible DoS attack. CVE-2025-69228 Possible DoS attack that can freeze the server by exhausting the memory using Request.post(). CVE-2025-69229 The handling of chunked messages that can result in an excessive blocking of CPU usage when receiving a large number of chunks. CVE-2026-22815 Uncapped memory usage due to insufficient restrictionsin header and trailer handling. CVE-2026-34513 Excessive memory usage possibly resulting in a DoS due to an an unbounded DNS cache. CVE-2026-34514 Header injection. CVE-2026-34516 Potential DoS vulnerability caused by a response with an excessive number of multipart headers. CVE-2026-34517 Possible excessive memory usage caused by some multipart form fields due to reading the entiry field into memory before checking client_max_size. CVE-2026-34518 Leaking sensitive information by dropping the Cookie and the Proxy- Authorization headers When following redirects to a different origin. CVE-2026-34519 Header injection via the reason parameter. CVE-2026-34520 Possible security bypass by checking header values for control characters accordingly to RFC 9110. CVE-2026-34525 Headers can be duplicated, e.g. the host header. For Debian 11 bullseye, these problems have been fixed in version 3.7.4-1+deb11u2. We recommend that you upgrade your python-aiohttp packages. For the detailed security status of python-aiohttp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/python-aiohttp Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Multiple vulnerabilities found in python-aiohttp requiring immediate upgrades for security enhancements and stability.. Debian python-aiohttp vulnerabilities DoS request smuggling. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 01, 2026 Important Debian LTS
203

Mageia 9 haproxy Important Request Smuggling Vulnerability MGASA-2026-0146

MGASA-2026-0146 - Updated haproxy packages fix security vulnerability . MGASA-2026-0146 - Updated haproxy packages fix security vulnerability Publication date: 16 May 2026 URL: https://advisories.mageia.org/MGASA-2026-0146.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-33555 Description: The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. (CVE-2026-33555) References: - https://bugs.mageia.org/show_bug.cgi?id=35416 - https://lists.opensuse.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/B3PXHUYDTDFG5IIQSPNJLLIEQV4Z5WK6/ - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33555 SRPMS: - 9/core/haproxy-2.8.18-1.1.mga9 . Updated haproxy packages in Mageia address critical HTTP/3 parser issue potentially compromising data integrity.. Mageia haproxy security patch HTTP/3 parser request smuggling. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 17, 2026 Important Mageia
100

SUSE 2026 Jetty Minimal Important Fixes for Access Control Issues

An update that solves two vulnerabilities can now be installed.. # Security update for jetty-minimal Announcement ID: SUSE-SU-2026:1751-1 Release Date: 2026-05-07T11:53:45Z Rating: important References: * bsc#1261997 * bsc#1262115 Cross-References: * CVE-2026-2332 * CVE-2026-5795 CVSS scores: * CVE-2026-2332 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-2332 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-2332 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-5795 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-5795 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-5795 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for jetty-minimal fixes the followingissues: * CVE-2026-2332: In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques (bsc#1262115). * CVE-2026-5795: Fixed JaspiAuthenticator broken access control (bsc#1261997). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-1751=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-1751=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1751=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1751=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1751=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1751=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1751=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1751=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1751=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1751=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1751=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1751=1 ## Package List: * DevelopmentTools Module 15-SP7 (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Package Hub 15 15-SP7 (noarch) * jetty-continuation-9.4.58-150200.3.40.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 *jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2332.html * https://www.suse.com/security/cve/CVE-2026-5795.html * https://bugzilla.suse.com/show_bug.cgi?id=1261997 *https://bugzilla.suse.com/show_bug.cgi?id=1262115 . Important security update for SUSE jetty-minimal addresses two vulnerabilities related to request smuggling and access control.. SUSE jetty-minimal important security access control request smuggling. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 07, 2026 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200