openSUSE-SU-2026:20919-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20919-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:20919-1
Upstream
CVE (4)
Related
Published
2026-06-08T10:21:35Z
Modified
2026-06-10T18:24:22Z
Summary
Security update for agama-web-ui
Details

This update for agama-web-ui fixes the following issues

  • CVE-2025-7339: on-headers: incorrect array handling may lead to HTTP response header manipulation (bsc#1246678).
  • CVE-2026-9277: shell-quote: improper escaping of newlines in object .op values by quote() can lead to shell command injection (bsc#1266256).
  • CVE-2026-42041: axios: authentication bypass via validateStatus prototype pollution gadget due to suppression of HTTP error (bsc#1264160).
  • CVE-2026-42264: axios: prototype pollution read-side gadgets in HTTP adapter can lead to credential injection and request h (bsc#1264802).

Changes for agama-web-ui:

  • Update other dependencies reported by "npm audit".
References

Affected packages

openSUSE:Leap 16.0 / agama-web-ui

Package

Name
agama-web-ui
Purl
pkg:rpm/opensuse/agama-web-ui&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
17+612.d8bf69336-160000.11.1

Ecosystem specific

{
    "binaries": [
        {
            "agama-web-ui": "17+612.d8bf69336-160000.11.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20919-1.json"