{"id":"openSUSE-SU-2026:20885-1","summary":"Security update for python-Flask","details":"This update for python-Flask fixes the following issue:\n\n- CVE-2026-27205: information disclosure due to Flask session not adding the `Vary: Cookie` header (bsc#1258700).\n","modified":"2026-06-04T18:24:16.946820566Z","published":"2026-06-02T17:26:26Z","related":["CVE-2026-27205"],"upstream":["CVE-2026-27205"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258700"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27205"}],"schema_version":"1.7.5"}