Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
202

openSUSE Leap 16.0 Advisory ID 2026-21066-1 Python Multipart Important DoS

An update that solves 4 vulnerabilities and has 4 bug fixes can now be installed.. openSUSE security update: security update for python-python-multipart ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21066-1 Rating: important References: * bsc#1268488 * bsc#1268496 * bsc#1268500 * bsc#1268506 Cross-References: * CVE-2026-53537 * CVE-2026-53538 * CVE-2026-53539 * CVE-2026-53540 CVSS scores: * CVE-2026-53537 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-53537 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53538 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-53538 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53539 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53539 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53540 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53540 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 4 vulnerabilities and has 4 bug fixes can now be installed. Description: This update for python-python-multipart fixes the following issues - CVE-2026-53537: multipart/form-data with extended parameters can lead to file or parameter smuggling (bsc#1268506). - CVE-2026-53538: urlencoded requests containing semicolons can lead to form field smuggling (bsc#1268496). - CVE-2026-53539: small crafted body can cause a denial of service (bsc#1268500). - CVE-2026-53540: crafted request buffers can lead to degrading availability (bsc#1268488). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the commandlisted for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1088=1 Package List: - openSUSE Leap 16.0: python313-python-multipart-0.0.20-160000.5.1 References: * https://www.suse.com/security/cve/CVE-2026-53537.html * https://www.suse.com/security/cve/CVE-2026-53538.html * https://www.suse.com/security/cve/CVE-2026-53539.html * https://www.suse.com/security/cve/CVE-2026-53540.html . This important security update for openSUSE addresses four key vulnerabilities affecting python-python-multipart.. openSUSE security update, python multipart vulnerabilities, security patch, Linux security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 Important OpenSUSE
100

SUSE libsoup Moderate HTTP Request Smuggling Vuln 2026-22071-1

An update that solves one vulnerability can now be installed.. # Security update for libsoup Announcement ID: SUSE-SU-2026:22071-1 Release Date: 2026-06-05T14:42:55Z Rating: moderate References: * bsc#1257649 Cross-References: * CVE-2026-1801 CVSS scores: * CVE-2026-1801 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1801 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-1801 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-1801 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for libsoup fixes the following issue * CVE-2026-1801: HTTP Request Smuggling in soup_filter_input_stream_read_line() (bsc#1257649). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-567=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libsoup-3_0-0-debuginfo-3.4.4-slfo.1.1_10.1 * libsoup-debugsource-3.4.4-slfo.1.1_10.1 * libsoup-3_0-0-3.4.4-slfo.1.1_10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1801.html * https://bugzilla.suse.com/show_bug.cgi?id=1257649 . Update for libsoup resolves a moderate issue with HTTP Request Smuggling vulnerability.. SUSE Security Update, libsoup Update, HTTP Request Smuggling. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 12, 2026 moderate SuSE
89

Fedora 43 perl-HTTP-Tiny Critical Header Smuggling Fix CVE-2026-7010

0.094 - fix to prevent invalid characters in all headers, and prevent header smuggling (CVE-2026-7010). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3bfb774625 2026-06-05 04:07:33.979891+00:00 -------------------------------------------------------------------------------- Name : perl-HTTP-Tiny Product : Fedora 43 Version : 0.094 Release : 1.fc43 URL : https://metacpan.org/release/HTTP-Tiny Summary : Small, simple, correct HTTP/1.1 client Description : This is a very simple HTTP/1.1 client, designed for doing simple GET requests without the overhead of a large framework like LWP::UserAgent. It is more correct and more complete than HTTP::Lite. It supports proxies (currently only non-authenticating ones) and redirection. It also correctly resumes after EINTR. -------------------------------------------------------------------------------- Update Information: 0.094 - fix to prevent invalid characters in all headers, and prevent header smuggling (CVE-2026-7010) -------------------------------------------------------------------------------- ChangeLog: * Wed May 20 2026 Jitka Plesnikova - 0.094-1 - 0.094 bump (rhbz#2478249) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2478249 - perl-HTTP-Tiny-0.094 is available https://bugzilla.redhat.com/show_bug.cgi?id=2478249 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3bfb774625' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . This advisory details security fixes for perl-HTTP-Tiny on Fedora 43 addressing header smuggling issues.. perl-HTTP-Tiny security patch, Fedora 43 update, header injection fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 05, 2026 Critical Fedora
99

Slackware: 2023-067-01 Critical: Httpd Request Smuggling Attack

New httpd packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] httpd (SSA:2023-067-01) New httpd packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/httpd-2.4.56-i586-1_slack15.0.txz: Upgraded. This update fixes two security issues: HTTP Response Smuggling vulnerability via mod_proxy_uwsgi. HTTP Request Smuggling attack via mod_rewrite and mod_proxy. For more information, see: https://www.cve.org/CVERecord?id=CVE-2023-27522 https://www.cve.org/CVERecord?id=CVE-2023-25690 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.0: Updated package for Slackware x86_64 14.0: Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware 14.2: Updated package for Slackware x86_64 14.2: Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.0 package: aa5ba4ca65ef5e2f1a556dce59499f53 httpd-2.4.56-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 6b3b96f0f263ce160c248e432feb9e22 httpd-2.4.56-x86_64-1_slack14.0.txz Slackware 14.1 package: 0466df1d0b695e06423b3b74e4b3001c httpd-2.4.56-i486-1_slack14.1.txz Slackware x86_64 14.1 package: 24c7e5cdc84dadc5dbb4d2492be91211 httpd-2.4.56-x86_64-1_slack14.1.txz Slackware 14.2 package: 44303214ead7652ff59b0482721c40a2 httpd-2.4.56-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 6d87a8aafce21046bf8182a72cb3adb3 httpd-2.4.56-x86_64-1_slack14.2.txz Slackware 15.0 package: eb75e6a814fadb936efa78bb394f37a2 httpd-2.4.56-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 66bc518f7d6aca2ea55f8da4979df3aa httpd-2.4.56-x86_64-1_slack15.0.txz Slackware -current package: 2c0db3136e67efd747d3305dfb1cc4a5 n/httpd-2.4.56-i586-1.txz Slackware x86_64 -current package: 3618ff7ab4a7253d1cd485b5c696fe8c n/httpd-2.4.56-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg httpd-2.4.56-i586-1_slack15.0.txz Then, restart Apache httpd: # /etc/rc.d/rc.httpd stop # /etc/rc.d/rc.httpd start +-----+ . Updated httpd versions for Slackware tackle urgent security vulnerabilities and enhance overall system reliability.. httpd Security Update,Slackware Packages,Response Smuggling,Request Smuggling,Security Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 08, 2023 Critical Slackware
203

Mageia 7: MGASA-2021-0123 Low: Undertow HTTP Request Smuggling Threat

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling (CVE-2020-10719). References: . MGASA-2021-0052 - Updated undertow packages fix security vulnerability Publication date: 22 Jan 2021 URL: https://advisories.mageia.org/MGASA-2021-0052.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-10719 A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling (CVE-2020-10719). References: - https://bugs.mageia.org/show_bug.cgi?id=28076 - https://security-tracker.debian.org/tracker/CVE-2020-10719 - https://www.cve.org/CVERecord?id=CVE-2020-10719 SRPMS: - 7/core/undertow-1.4.0-2.1.mga7 . Improvements for Undertow rectify a vulnerability allowing HTTP request smuggling exploits in Mageia 7 environments. Security measures detailed.. Mageia Update, Undertow Security, HTTP Request Fix. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Jan 22, 2021 Low Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200