Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
SUSE-SU-2026:21993-1
See a problem?
Please try reporting it
to the source
first.
Source
https://www.suse.com/support/update/announcement/2026/suse-su-202621993-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21993-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:21993-1
Upstream
CVE-2026-31958
Related
CVE-2026-31958
Published
2026-06-03T12:59:25Z
Modified
2026-06-06T18:24:19Z
Summary
Security update for salt
Details
This update for salt fixes the following issues:
Security issues fixed:
CVE-2026-31958: tornado: Fixed parsing large multipart bodies with many parts can cause a denial of service (bsc#1259554)
Other updates and bugfixes:
Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700)
Hardened Tornado from invalid HTTP reason phrases
Read full URI from ldap pillar config (bsc#1254900)
Fixed testsuite failures
Make users with backslash working for salt-ssh (bsc#1254629)
Fixed ansible.playbooks extra-vars quoting (bsc#1257831)
Fixed virtualenv call in test helper to use proper python version
References
https://www.suse.com/support/update/announcement/2026/suse-su-202621993-1/
https://bugzilla.suse.com/1254629
https://bugzilla.suse.com/1254900
https://bugzilla.suse.com/1257583
https://bugzilla.suse.com/1257831
https://bugzilla.suse.com/1259554
https://bugzilla.suse.com/1259700
https://www.suse.com/security/cve/CVE-2026-31958
Affected packages
SUSE-SU-2026:21993-1 - OSV