SUSE-SU-2026:21785-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202621785-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21785-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:21785-1
Upstream
CVE (2)
Related
Published
2026-05-22T09:42:26Z
Modified
2026-05-28T18:24:00Z
Summary
Security update for cockpit
Details

This update for cockpit fixes the following issues

  • CVE-2026-4802: remote command execution via unsanitized user-controlled parameters within crafted links in system logs UI (bsc#1265040).
  • CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive CPU and memory consumption and may crash a Node.js process (bsc#1257836).
References

Affected packages