Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 4 vulnerabilities and has 4 bug fixes can now be installed.. openSUSE security update: security update for python-python-multipart ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21066-1 Rating: important References: * bsc#1268488 * bsc#1268496 * bsc#1268500 * bsc#1268506 Cross-References: * CVE-2026-53537 * CVE-2026-53538 * CVE-2026-53539 * CVE-2026-53540 CVSS scores: * CVE-2026-53537 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-53537 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53538 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-53538 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53539 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53539 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53540 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53540 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 4 vulnerabilities and has 4 bug fixes can now be installed. Description: This update for python-python-multipart fixes the following issues - CVE-2026-53537: multipart/form-data with extended parameters can lead to file or parameter smuggling (bsc#1268506). - CVE-2026-53538: urlencoded requests containing semicolons can lead to form field smuggling (bsc#1268496). - CVE-2026-53539: small crafted body can cause a denial of service (bsc#1268500). - CVE-2026-53540: crafted request buffers can lead to degrading availability (bsc#1268488). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the commandlisted for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1088=1 Package List: - openSUSE Leap 16.0: python313-python-multipart-0.0.20-160000.5.1 References: * https://www.suse.com/security/cve/CVE-2026-53537.html * https://www.suse.com/security/cve/CVE-2026-53538.html * https://www.suse.com/security/cve/CVE-2026-53539.html * https://www.suse.com/security/cve/CVE-2026-53540.html . This important security update for openSUSE addresses four key vulnerabilities affecting python-python-multipart.. openSUSE security update, python multipart vulnerabilities, security patch, Linux security advisory. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for libsoup Announcement ID: SUSE-SU-2026:22071-1 Release Date: 2026-06-05T14:42:55Z Rating: moderate References: * bsc#1257649 Cross-References: * CVE-2026-1801 CVSS scores: * CVE-2026-1801 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1801 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-1801 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-1801 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for libsoup fixes the following issue * CVE-2026-1801: HTTP Request Smuggling in soup_filter_input_stream_read_line() (bsc#1257649). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-567=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libsoup-3_0-0-debuginfo-3.4.4-slfo.1.1_10.1 * libsoup-debugsource-3.4.4-slfo.1.1_10.1 * libsoup-3_0-0-3.4.4-slfo.1.1_10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1801.html * https://bugzilla.suse.com/show_bug.cgi?id=1257649 . Update for libsoup resolves a moderate issue with HTTP Request Smuggling vulnerability.. SUSE Security Update, libsoup Update, HTTP Request Smuggling. . Severity: moderate. LinuxSecurity.com Team
0.094 - fix to prevent invalid characters in all headers, and prevent header smuggling (CVE-2026-7010). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3bfb774625 2026-06-05 04:07:33.979891+00:00 -------------------------------------------------------------------------------- Name : perl-HTTP-Tiny Product : Fedora 43 Version : 0.094 Release : 1.fc43 URL : https://metacpan.org/release/HTTP-Tiny Summary : Small, simple, correct HTTP/1.1 client Description : This is a very simple HTTP/1.1 client, designed for doing simple GET requests without the overhead of a large framework like LWP::UserAgent. It is more correct and more complete than HTTP::Lite. It supports proxies (currently only non-authenticating ones) and redirection. It also correctly resumes after EINTR. -------------------------------------------------------------------------------- Update Information: 0.094 - fix to prevent invalid characters in all headers, and prevent header smuggling (CVE-2026-7010) -------------------------------------------------------------------------------- ChangeLog: * Wed May 20 2026 Jitka Plesnikova - 0.094-1 - 0.094 bump (rhbz#2478249) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2478249 - perl-HTTP-Tiny-0.094 is available https://bugzilla.redhat.com/show_bug.cgi?id=2478249 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3bfb774625' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
New httpd packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] httpd (SSA:2023-067-01) New httpd packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/httpd-2.4.56-i586-1_slack15.0.txz: Upgraded. This update fixes two security issues: HTTP Response Smuggling vulnerability via mod_proxy_uwsgi. HTTP Request Smuggling attack via mod_rewrite and mod_proxy. For more information, see: https://www.cve.org/CVERecord?id=CVE-2023-27522 https://www.cve.org/CVERecord?id=CVE-2023-25690 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.0: Updated package for Slackware x86_64 14.0: Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware 14.2: Updated package for Slackware x86_64 14.2: Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.0 package: aa5ba4ca65ef5e2f1a556dce59499f53 httpd-2.4.56-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 6b3b96f0f263ce160c248e432feb9e22 httpd-2.4.56-x86_64-1_slack14.0.txz Slackware 14.1 package: 0466df1d0b695e06423b3b74e4b3001c httpd-2.4.56-i486-1_slack14.1.txz Slackware x86_64 14.1 package: 24c7e5cdc84dadc5dbb4d2492be91211 httpd-2.4.56-x86_64-1_slack14.1.txz Slackware 14.2 package: 44303214ead7652ff59b0482721c40a2 httpd-2.4.56-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 6d87a8aafce21046bf8182a72cb3adb3 httpd-2.4.56-x86_64-1_slack14.2.txz Slackware 15.0 package: eb75e6a814fadb936efa78bb394f37a2 httpd-2.4.56-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 66bc518f7d6aca2ea55f8da4979df3aa httpd-2.4.56-x86_64-1_slack15.0.txz Slackware -current package: 2c0db3136e67efd747d3305dfb1cc4a5 n/httpd-2.4.56-i586-1.txz Slackware x86_64 -current package: 3618ff7ab4a7253d1cd485b5c696fe8c n/httpd-2.4.56-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg httpd-2.4.56-i586-1_slack15.0.txz Then, restart Apache httpd: # /etc/rc.d/rc.httpd stop # /etc/rc.d/rc.httpd start +-----+ . Updated httpd versions for Slackware tackle urgent security vulnerabilities and enhance overall system reliability.. httpd Security Update,Slackware Packages,Response Smuggling,Request Smuggling,Security Issues. . Severity: Critical. LinuxSecurity.com Team
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling (CVE-2020-10719). References: . MGASA-2021-0052 - Updated undertow packages fix security vulnerability Publication date: 22 Jan 2021 URL: https://advisories.mageia.org/MGASA-2021-0052.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-10719 A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling (CVE-2020-10719). References: - https://bugs.mageia.org/show_bug.cgi?id=28076 - https://security-tracker.debian.org/tracker/CVE-2020-10719 - https://www.cve.org/CVERecord?id=CVE-2020-10719 SRPMS: - 7/core/undertow-1.4.0-2.1.mga7 . Improvements for Undertow rectify a vulnerability allowing HTTP request smuggling exploits in Mageia 7 environments. Security measures detailed.. Mageia Update, Undertow Security, HTTP Request Fix. . Severity: Low. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.