{"id":"SUSE-SU-2026:1745-1","summary":"Security update for rmt-server","details":"This update for rmt-server fixes the following issues:\n\nUpdate to version 2.27.\n\nSecurity issues fixed:\n\n- CVE-2026-26961: rack: greedy multipart boundary parsing can lead to parser differentials and WAF bypass\n  (bsc#1261398).\n- CVE-2026-26962: rack: improper unfolding of folded multipart headers can lead to downstream header injection and\n  response splitting(bsc#1261471).  \n- CVE-2026-34763: rack: unescaped regex interpolation of configured root path can lead to root directory disclosure\n  (bsc#1261406).\n- CVE-2026-34785: rack: prefix matching logic can lead to the exposure of unintended files under the static root\n  (bsc#1261417).\n- CVE-2026-34786: rack: URL-encoded path mismatch can lead to `header_rules` bypass (bsc#1261426).\n- CVE-2026-34826: rack: missing individual byte range limit checks when parsing HTTP `Range` headers can lead to\n  excessive resource consumption and a denial of service (bsc#1261436).\n- CVE-2026-34829: rack: multipart parsing without `Content-Length` header can lead to unbounded chunked file uploads\n  and a denial of service (bsc#1261447).\n- CVE-2026-34230: rack: quadratic complexity when processing of wildcard `Accept-Encoding` headers can lead to a denial\n  of service (bsc#1261388).  \n- CVE-2026-34830: rack: improper sanitization of the `X-Accel-Mapping` request header can lead to the exposure of\n  unintended files via `X-Accel-Redirect` (bsc#1261458).\n- CVE-2026-34831: rack: `Content-Length` header and body byte size mismatch when creating error responses can lead to\n  incorrect HTTP response framing (bsc#1261466).\n\nOther updates and bugfixes:\n\n- Fix ReDoS in `Addressable`.\n- Fix out-of-bounds read in `rdiscount`.\n","modified":"2026-05-08T08:15:10.557924Z","published":"2026-05-07T07:22:43Z","related":["CVE-2026-26961","CVE-2026-26962","CVE-2026-34230","CVE-2026-34763","CVE-2026-34785","CVE-2026-34786","CVE-2026-34826","CVE-2026-34829","CVE-2026-34830","CVE-2026-34831"],"upstream":["CVE-2026-26961","CVE-2026-26962","CVE-2026-34230","CVE-2026-34763","CVE-2026-34785","CVE-2026-34786","CVE-2026-34826","CVE-2026-34829","CVE-2026-34830","CVE-2026-34831"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261745-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261388"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261398"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261406"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261417"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261426"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261436"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261447"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261458"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261466"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261471"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26961"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26962"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34230"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34763"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34785"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34786"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34826"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34829"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34830"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34831"}],"schema_version":"1.7.5"}