{"id":"SUSE-SU-2026:2487-1","summary":"Security update for rmt-server","details":"This update for rmt-server fixes the following issues\n\n- CVE-2026-26961: rack: mismatch in header handling can allow to smuggle multipart content (bsc#1261398).\n- CVE-2026-26962: rack: improper unfolding of folded multipart headers can lead to header injection or response\n  splitting (bsc#1261471).\n- CVE-2026-34230: rack: crafted Accept-Encoding header can cause a denial of service (bsc#1261388).\n- CVE-2026-34763: rack: failing of the prefix stripping can lead to information disclosure (bsc#1261406).\n- CVE-2026-34785: rack: prefix matching can expose unintended files under the static root (bsc#1261417).\n- CVE-2026-34786: rack: URL-encoded path mismatch can lead to `header_rules` bypass (bsc#1261426).\n- CVE-2026-34826: rack: multipart byte range processing can allow denial of service (bsc#1261436).\n- CVE-2026-34829: rack: multipart parsing without `Content-Length` header allows unbounded chunked file uploads\n  (bsc#1261447).\n- CVE-2026-34830: rack: crafted `X-Accel-Mapping`headers can lead to regex injection (bsc#1261458).\n- CVE-2026-34831: rack: `Content-Length` mismatch can lead to incorrectly framed error responses (bsc#1261466).\n\nChanges for rmt-server:\n\n- Updated to version 2.27\n","modified":"2026-06-24T09:00:05.466533044Z","published":"2026-06-22T12:08:31Z","related":["CVE-2026-26961","CVE-2026-26962","CVE-2026-34230","CVE-2026-34763","CVE-2026-34785","CVE-2026-34786","CVE-2026-34826","CVE-2026-34829","CVE-2026-34830","CVE-2026-34831"],"upstream":["CVE-2026-26961","CVE-2026-26962","CVE-2026-34230","CVE-2026-34763","CVE-2026-34785","CVE-2026-34786","CVE-2026-34826","CVE-2026-34829","CVE-2026-34830","CVE-2026-34831"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262487-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246976"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261388"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261398"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261406"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261417"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261426"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261436"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261447"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261458"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261466"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261471"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26961"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26962"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34230"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34763"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34785"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34786"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34826"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34829"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34830"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34831"}],"affected":[{"package":{"name":"rmt-server","ecosystem":"SUSE:Linux Enterprise Module for Public Cloud 15 SP5","purl":"pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.27-150500.3.47.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server-pubcloud":"2.27-150500.3.47.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2487-1.json"}},{"package":{"name":"rmt-server","ecosystem":"SUSE:Linux Enterprise Module for Public Cloud 15 SP6","purl":"pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.27-150500.3.47.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server-pubcloud":"2.27-150500.3.47.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2487-1.json"}},{"package":{"name":"rmt-server","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.27-150500.3.47.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server-config":"2.27-150500.3.47.1","rmt-server":"2.27-150500.3.47.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2487-1.json"}},{"package":{"name":"rmt-server","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.27-150500.3.47.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server":"2.27-150500.3.47.1","rmt-server-config":"2.27-150500.3.47.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2487-1.json"}},{"package":{"name":"rmt-server","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.27-150500.3.47.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server":"2.27-150500.3.47.1","rmt-server-config":"2.27-150500.3.47.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2487-1.json"}},{"package":{"name":"rmt-server","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.27-150500.3.47.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server-config":"2.27-150500.3.47.1","rmt-server":"2.27-150500.3.47.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2487-1.json"}},{"package":{"name":"rmt-server","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.27-150500.3.47.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server-config":"2.27-150500.3.47.1","rmt-server":"2.27-150500.3.47.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2487-1.json"}},{"package":{"name":"rmt-server","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.27-150500.3.47.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server":"2.27-150500.3.47.1","rmt-server-config":"2.27-150500.3.47.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2487-1.json"}}],"schema_version":"1.7.5"}