SUSE-SU-2026:0643-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20260643-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0643-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:0643-1
Upstream
Related
Published
2026-02-25T16:27:51Z
Modified
2026-02-26T23:51:18.172816Z
Summary
Security update for python39
Details

This update for python39 fixes the following issues:

  • CVE-2025-11468: Fixed a header injection when folding a long comment in an email header containing exclusively unfoldable characters. (bsc#1257029)
  • CVE-2026-0672: Fixed a HTTP header injection via user-controlled cookie values and parameters when using http.cookies.Morsel. (bsc#1257031)
  • CVE-2026-0865: Fixed a bug where a user-controlled header containing newlines can allow injecting HTTP headers. (bsc#1257042)
  • CVE-2025-15282: Fixed a bug where a user-controlled data URLs parsed may allow injecting headers. (bsc#1257046)
  • CVE-2025-15366: Fixed a bug wherer a user-controlled command can allow additional commands injected using newlines. (bsc#1257044)
  • CVE-2025-15367: Fixed control characters which may allow the injection of additional commands. (bsc#1257041)
References

Affected packages

openSUSE:Leap 15.6
python39

Package

Name
python39
Purl
pkg:rpm/opensuse/python39&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.25-150300.4.93.1

Ecosystem specific

{
    "binaries": [
        {
            "libpython3_9-1_0": "3.9.25-150300.4.93.1",
            "python39-doc": "3.9.25-150300.4.93.1",
            "python39-doc-devhelp": "3.9.25-150300.4.93.1",
            "python39-idle": "3.9.25-150300.4.93.1",
            "python39-base-32bit": "3.9.25-150300.4.93.1",
            "python39-curses": "3.9.25-150300.4.93.1",
            "python39-32bit": "3.9.25-150300.4.93.1",
            "python39-dbm": "3.9.25-150300.4.93.1",
            "python39-testsuite": "3.9.25-150300.4.93.1",
            "python39-tk": "3.9.25-150300.4.93.1",
            "python39-tools": "3.9.25-150300.4.93.1",
            "python39-base": "3.9.25-150300.4.93.1",
            "libpython3_9-1_0-32bit": "3.9.25-150300.4.93.1",
            "python39": "3.9.25-150300.4.93.1",
            "python39-devel": "3.9.25-150300.4.93.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0643-1.json"
python39-core

Package

Name
python39-core
Purl
pkg:rpm/opensuse/python39-core&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.25-150300.4.93.1

Ecosystem specific

{
    "binaries": [
        {
            "libpython3_9-1_0": "3.9.25-150300.4.93.1",
            "python39-doc": "3.9.25-150300.4.93.1",
            "python39-doc-devhelp": "3.9.25-150300.4.93.1",
            "python39-idle": "3.9.25-150300.4.93.1",
            "python39-base-32bit": "3.9.25-150300.4.93.1",
            "python39-curses": "3.9.25-150300.4.93.1",
            "python39-32bit": "3.9.25-150300.4.93.1",
            "python39-dbm": "3.9.25-150300.4.93.1",
            "python39-testsuite": "3.9.25-150300.4.93.1",
            "python39-tk": "3.9.25-150300.4.93.1",
            "python39-tools": "3.9.25-150300.4.93.1",
            "python39-base": "3.9.25-150300.4.93.1",
            "libpython3_9-1_0-32bit": "3.9.25-150300.4.93.1",
            "python39": "3.9.25-150300.4.93.1",
            "python39-devel": "3.9.25-150300.4.93.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0643-1.json"
python39-documentation

Package

Name
python39-documentation
Purl
pkg:rpm/opensuse/python39-documentation&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.25-150300.4.93.1

Ecosystem specific

{
    "binaries": [
        {
            "libpython3_9-1_0": "3.9.25-150300.4.93.1",
            "python39-doc": "3.9.25-150300.4.93.1",
            "python39-doc-devhelp": "3.9.25-150300.4.93.1",
            "python39-idle": "3.9.25-150300.4.93.1",
            "python39-base-32bit": "3.9.25-150300.4.93.1",
            "python39-curses": "3.9.25-150300.4.93.1",
            "python39-32bit": "3.9.25-150300.4.93.1",
            "python39-dbm": "3.9.25-150300.4.93.1",
            "python39-testsuite": "3.9.25-150300.4.93.1",
            "python39-tk": "3.9.25-150300.4.93.1",
            "python39-tools": "3.9.25-150300.4.93.1",
            "python39-base": "3.9.25-150300.4.93.1",
            "libpython3_9-1_0-32bit": "3.9.25-150300.4.93.1",
            "python39": "3.9.25-150300.4.93.1",
            "python39-devel": "3.9.25-150300.4.93.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0643-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
python39

Package

Name
python39
Purl
pkg:rpm/suse/python39&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.25-150300.4.93.1

Ecosystem specific

{
    "binaries": [
        {
            "python39-curses": "3.9.25-150300.4.93.1",
            "python39-base": "3.9.25-150300.4.93.1",
            "python39-dbm": "3.9.25-150300.4.93.1",
            "python39": "3.9.25-150300.4.93.1",
            "libpython3_9-1_0": "3.9.25-150300.4.93.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0643-1.json"
python39-core

Package

Name
python39-core
Purl
pkg:rpm/suse/python39-core&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.25-150300.4.93.1

Ecosystem specific

{
    "binaries": [
        {
            "python39-curses": "3.9.25-150300.4.93.1",
            "python39-base": "3.9.25-150300.4.93.1",
            "python39-dbm": "3.9.25-150300.4.93.1",
            "python39": "3.9.25-150300.4.93.1",
            "libpython3_9-1_0": "3.9.25-150300.4.93.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0643-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
python39

Package

Name
python39
Purl
pkg:rpm/suse/python39&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.25-150300.4.93.1

Ecosystem specific

{
    "binaries": [
        {
            "python39-curses": "3.9.25-150300.4.93.1",
            "python39-base": "3.9.25-150300.4.93.1",
            "python39-dbm": "3.9.25-150300.4.93.1",
            "python39": "3.9.25-150300.4.93.1",
            "libpython3_9-1_0": "3.9.25-150300.4.93.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0643-1.json"
python39-core

Package

Name
python39-core
Purl
pkg:rpm/suse/python39-core&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.25-150300.4.93.1

Ecosystem specific

{
    "binaries": [
        {
            "python39-curses": "3.9.25-150300.4.93.1",
            "python39-base": "3.9.25-150300.4.93.1",
            "python39-dbm": "3.9.25-150300.4.93.1",
            "python39": "3.9.25-150300.4.93.1",
            "libpython3_9-1_0": "3.9.25-150300.4.93.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0643-1.json"