{"id":"SUSE-SU-2026:2464-1","summary":"Security update for python313","details":"This update for python313 fixes the following issues\n\nSecurity issues:\n\n- CVE-2026-1502: HTTP client proxy tunnel headers not validated for CR/LF (bsc#1261969).\n- CVE-2026-3446: Base64 decoding stops at first padded quad by default (bsc#1261970).\n- CVE-2026-4786: [oss-security][] CPython: Incomplete mitigation of , %action expansion for command injection to\n  webbrowser.open() (bsc#1262319).\n- CVE-2026-6019: `BaseCookie.js_output()` does not neutralize characters in cookie values embedded in JS (bsc#1262654).\n- CVE-2026-6100: Arbitrary code execution or information disclosure via use-after-free in decompression modules\n  (bsc#1262098).\n\nNon security issue:\n\n- Add missing BR `crypto-policies-scripts` (need for the fix of bsc#1211301).\n","modified":"2026-06-20T08:45:04.558468655Z","published":"2026-06-19T09:44:32Z","related":["CVE-2026-1502","CVE-2026-3446","CVE-2026-4786","CVE-2026-6019","CVE-2026-6100"],"upstream":["CVE-2026-1502","CVE-2026-3446","CVE-2026-4786","CVE-2026-6019","CVE-2026-6100"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262464-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1211301"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261969"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261970"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262098"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262319"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262654"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263787"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1502"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3446"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4786"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6019"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6100"}],"affected":[{"package":{"name":"python313","ecosystem":"SUSE:Linux Enterprise Module for Python 3 15 SP7","purl":"pkg:rpm/suse/python313&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%203%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.13.13-150700.4.50.1"}]}],"ecosystem_specific":{"binaries":[{"python313-base":"3.13.13-150700.4.50.1","libpython3_13-1_0":"3.13.13-150700.4.50.1","python313-tk":"3.13.13-150700.4.50.1","python313-dbm":"3.13.13-150700.4.50.1","python313-curses":"3.13.13-150700.4.50.1","python313-tools":"3.13.13-150700.4.50.1","python313":"3.13.13-150700.4.50.1","python313-idle":"3.13.13-150700.4.50.1","python313-devel":"3.13.13-150700.4.50.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2464-1.json"}},{"package":{"name":"python313-core","ecosystem":"SUSE:Linux Enterprise Module for Python 3 15 SP7","purl":"pkg:rpm/suse/python313-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%203%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.13.13-150700.4.50.1"}]}],"ecosystem_specific":{"binaries":[{"python313-idle":"3.13.13-150700.4.50.1","python313-tools":"3.13.13-150700.4.50.1","python313":"3.13.13-150700.4.50.1","python313-tk":"3.13.13-150700.4.50.1","python313-base":"3.13.13-150700.4.50.1","python313-devel":"3.13.13-150700.4.50.1","python313-curses":"3.13.13-150700.4.50.1","python313-dbm":"3.13.13-150700.4.50.1","libpython3_13-1_0":"3.13.13-150700.4.50.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2464-1.json"}}],"schema_version":"1.7.5"}