Explore top 10 tips to secure your open-source projects now. Read More
×
Backport upstream fixes for CVE-2026-54387 and CVE-2026-54388.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-efbe094630 2026-06-27 01:10:00.374896+00:00 -------------------------------------------------------------------------------- Name : tinyproxy Product : Fedora 44 Version : 1.11.2 Release : 8.fc44 URL : https://tinyproxy.github.io/ Summary : A small, efficient HTTP/SSL proxy daemon Description : tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a small network setting, where a larger proxy like Squid would either be too resource intensive, or a security risk. -------------------------------------------------------------------------------- Update Information: Backport upstream fixes for CVE-2026-54387 and CVE-2026-54388. -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 18 2026 Carl George - 1.11.2-8 - Backport upstream CVE fixes - Fixes CVE-2026-54387 - Fixes CVE-2026-54388 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2490299 - CVE-2026-54387 tinyproxy: HTTP Request Smuggling via CL/TE desynchronization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490299 [ 2 ] Bug #2490301 - CVE-2026-54388 tinyproxy: HTTP Request Smuggling via duplicate Content-Length headers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490301 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-efbe094630' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Backport upstream fixes for CVE-2026-54387 and CVE-2026-54388.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-77f1ca9c8f 2026-06-27 00:54:50.049783+00:00 -------------------------------------------------------------------------------- Name : tinyproxy Product : Fedora 43 Version : 1.11.2 Release : 8.fc43 URL : https://tinyproxy.github.io/ Summary : A small, efficient HTTP/SSL proxy daemon Description : tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a small network setting, where a larger proxy like Squid would either be too resource intensive, or a security risk. -------------------------------------------------------------------------------- Update Information: Backport upstream fixes for CVE-2026-54387 and CVE-2026-54388. -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 18 2026 Carl George - 1.11.2-8 - Backport upstream CVE fixes - Fixes CVE-2026-54387 - Fixes CVE-2026-54388 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2490299 - CVE-2026-54387 tinyproxy: HTTP Request Smuggling via CL/TE desynchronization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490299 [ 2 ] Bug #2490301 - CVE-2026-54388 tinyproxy: HTTP Request Smuggling via duplicate Content-Length headers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490301 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-77f1ca9c8f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability can now be installed.. # Security update for libsoup Announcement ID: SUSE-SU-2026:22061-1 Release Date: 2026-06-05T15:20:34Z Rating: moderate References: * bsc#1257649 Cross-References: * CVE-2026-1801 CVSS scores: * CVE-2026-1801 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1801 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-1801 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-1801 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for libsoup fixes the following issue * CVE-2026-1801: HTTP Request Smuggling in soup_filter_input_stream_read_line() (bsc#1257649). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-743=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libsoup-3_0-0-3.4.2-16.1 * libsoup-debugsource-3.4.2-16.1 * libsoup-3_0-0-debuginfo-3.4.2-16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1801.html * https://bugzilla.suse.com/show_bug.cgi?id=1257649 . Discover the latest SUSE security advisory for libsoup addressing a moderate HTTP Request Smuggling issue.. SUSE Security Update, libsoup Security Patch, HTTP Request Smuggling, SUSE Linux Micro, CVE-2026-1801. . Severity: moderate. LinuxSecurity.com Team
Several security issues were fixed in Netty.. ========================================================================== Ubuntu Security Notice USN-8401-1 June 08, 2026 netty vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Netty. Software Description: - netty: event-driven asynchronous network application framework Details: It was discovered that Netty's HTTP proxy handler did not properly validate headers when constructing CONNECT requests. An attacker could possibly use this issue to inject arbitrary HTTP headers into CONNECT requests. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42578) It was discovered that Netty's DNS codec did not properly enforce domain name constraints. An attacker could possibly use this issue to bypass domain name validation, or cause Netty to consume resources, leading to a denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42579) It was discovered that Netty did not correctly handle HTTP/1.0 requests containing both a Transfer-Encoding and Content-Length header. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks. (CVE-2026-42581) Violeta Georgieva discovered that Netty incorrectly paired responses with requests when handling informational HTTP responses. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks. (CVE-2026-42584) Violeta Georgieva discovered that Netty incorrectly parsed malformed Transfer-Encoding headers. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks. (CVE-2026-42585) It was discovered thatNetty's Redis encoder did not validate CRLF characters. An attacker could possibly use this issue to inject arbitrary Redis commands. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42586) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libnetty-java 1:4.1.48-16ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 24.04 LTS libnetty-java 1:4.1.48-9ubuntu0.1+esm3 Available with Ubuntu Pro Ubuntu 22.04 LTS libnetty-java 1:4.1.48-4+deb11u2ubuntu0.1+esm3 Available with Ubuntu Pro Ubuntu 20.04 LTS libnetty-java 1:4.1.45-1ubuntu0.1~esm6 Available with Ubuntu Pro Ubuntu 18.04 LTS libnetty-java 1:4.1.7-4ubuntu0.1+esm6 Available with Ubuntu Pro Ubuntu 16.04 LTS libnetty-java 1:4.0.34-1ubuntu0.1~esm4 Available with Ubuntu Pro Ubuntu 14.04 LTS libnetty-java 1:3.2.6.Final-2+deb8u2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8401-1 CVE-2026-42578, CVE-2026-42579, CVE-2026-42581, CVE-2026-42584, CVE-2026-42585, CVE-2026-42586 . Netty vulnerabilities in Ubuntu require updates to prevent request smuggling and denial of service attacks. Stay secure!. Ubuntu Netty security fix, request smuggling Ubuntu, Denial of Service Netty, security advisory update, arbitrary command injection. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in Netty.. ========================================================================== Ubuntu Security Notice USN-8401-1 June 08, 2026 netty vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Netty. Software Description: - netty: event-driven asynchronous network application framework Details: It was discovered that Netty's HTTP proxy handler did not properly validate headers when constructing CONNECT requests. An attacker could possibly use this issue to inject arbitrary HTTP headers into CONNECT requests. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42578) It was discovered that Netty's DNS codec did not properly enforce domain name constraints. An attacker could possibly use this issue to bypass domain name validation, or cause Netty to consume resources, leading to a denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42579) It was discovered that Netty did not correctly handle HTTP/1.0 requests containing both a Transfer-Encoding and Content-Length header. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks. (CVE-2026-42581) Violeta Georgieva discovered that Netty incorrectly paired responses with requests when handling informational HTTP responses. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks. (CVE-2026-42584) Violeta Georgieva discovered that Netty incorrectly parsed malformed Transfer-Encoding headers. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks. (CVE-2026-42585) It was discovered thatNetty's Redis encoder did not validate CRLF characters. An attacker could possibly use this issue to inject arbitrary Redis commands. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42586) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libnetty-java 1:4.1.48-16ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 24.04 LTS libnetty-java 1:4.1.48-9ubuntu0.1+esm3 Available with Ubuntu Pro Ubuntu 22.04 LTS libnetty-java 1:4.1.48-4+deb11u2ubuntu0.1+esm3 Available with Ubuntu Pro Ubuntu 20.04 LTS libnetty-java 1:4.1.45-1ubuntu0.1~esm6 Available with Ubuntu Pro Ubuntu 18.04 LTS libnetty-java 1:4.1.7-4ubuntu0.1+esm6 Available with Ubuntu Pro Ubuntu 16.04 LTS libnetty-java 1:4.0.34-1ubuntu0.1~esm4 Available with Ubuntu Pro Ubuntu 14.04 LTS libnetty-java 1:3.2.6.Final-2+deb8u2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8401-1 CVE-2026-42578, CVE-2026-42579, CVE-2026-42581, CVE-2026-42584, CVE-2026-42585, CVE-2026-42586 . Multiple critical issues fixed in Netty for Ubuntu affecting various LTS releases, including HTTP injection and DoS risks.. Ubuntu security, Netty fixes, HTTP smuggling. . Severity: Critical. LinuxSecurity.com Team
Several vulnerabilities have been found in aiohttp, an asynchronous HTTP client/server framework for asyncio and Python. CVE-2025-53643 Request smuggling vulnerability due to not parsing trailer sections of an HTTP request.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4613-1
MGASA-2026-0146 - Updated haproxy packages fix security vulnerability . MGASA-2026-0146 - Updated haproxy packages fix security vulnerability Publication date: 16 May 2026 URL: https://advisories.mageia.org/MGASA-2026-0146.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-33555 Description: The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. (CVE-2026-33555) References: - https://bugs.mageia.org/show_bug.cgi?id=35416 - https://lists.opensuse.org/archives/list/
An update that solves two vulnerabilities can now be installed.. # Security update for jetty-minimal Announcement ID: SUSE-SU-2026:1751-1 Release Date: 2026-05-07T11:53:45Z Rating: important References: * bsc#1261997 * bsc#1262115 Cross-References: * CVE-2026-2332 * CVE-2026-5795 CVSS scores: * CVE-2026-2332 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-2332 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-2332 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-5795 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-5795 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-5795 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for jetty-minimal fixes the followingissues: * CVE-2026-2332: In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques (bsc#1262115). * CVE-2026-5795: Fixed JaspiAuthenticator broken access control (bsc#1261997). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-1751=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-1751=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1751=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1751=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1751=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1751=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1751=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1751=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1751=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1751=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1751=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1751=1 ## Package List: * DevelopmentTools Module 15-SP7 (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Package Hub 15 15-SP7 (noarch) * jetty-continuation-9.4.58-150200.3.40.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 *jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * jetty-http-9.4.58-150200.3.40.1 * jetty-security-9.4.58-150200.3.40.1 * jetty-servlet-9.4.58-150200.3.40.1 * jetty-io-9.4.58-150200.3.40.1 * jetty-util-9.4.58-150200.3.40.1 * jetty-util-ajax-9.4.58-150200.3.40.1 * jetty-server-9.4.58-150200.3.40.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2332.html * https://www.suse.com/security/cve/CVE-2026-5795.html * https://bugzilla.suse.com/show_bug.cgi?id=1261997 *https://bugzilla.suse.com/show_bug.cgi?id=1262115 . Important security update for SUSE jetty-minimal addresses two vulnerabilities related to request smuggling and access control.. SUSE jetty-minimal important security access control request smuggling. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.