{"id":"openSUSE-SU-2026:21163-1","summary":"Security update for yt-dlp","details":"This update for yt-dlp fixes the following issues:\n\nChanges in yt-dlp:\n\n- Update to version 2026.06.09\n  * Fixed [CVE-2026-50019]: File Downloader cookie leak with curl\n  * Fixed [CVE-2026-50023]: Dangerous file type creation via\n    insufficient filename sanitization\n  * Fixed [CVE-2026-50574]: Arbitrary code execution via manifest\n    downloads with aria2c\n  * Added lockfile and pinned extras\n  * Removed url, desktop and webloc from safe extensions\n  * Extract supplemental codecs from DASH manifests\n  * abematv: Extract subtitles\n  * ard: Support new ardsounds domain\n  * monstercat: Support older URLs\n  * pornhub: Support browser impersonation\n  * reddit: Fix unauthenticated extraction\n  * rtp: Support multi-part episodes and --no-playlist\n  * s4c: Extract more metadata\n  * soop: Adapt extractors to new domain\n  * soundcloud: Support --extractor-retries for original formats\n  * twitch: Remove dead rechat subtitles\n  * twitter: Fix view_count extraction\n  * external: aria2c: Remove support for m3u8/dash protocols\n  * ffmpegmetadata: Avoid erroneous ISO 639 conversions\n","modified":"2026-06-30T18:24:49.979270580Z","published":"2026-06-29T08:10:11Z","related":["CVE-2026-50019","CVE-2026-50023","CVE-2026-50574"],"upstream":["CVE-2026-50019","CVE-2026-50023","CVE-2026-50574"],"references":[{"type":"ADVISORY"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50019"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50023"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50574"}],"affected":[{"package":{"name":"yt-dlp","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/yt-dlp&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2026.06.09-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"yt-dlp":"2026.06.09-bp160.1.1","yt-dlp-youtube-dl":"2026.06.09-bp160.1.1","python313-yt-dlp":"2026.06.09-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21163-1.json"}}],"schema_version":"1.7.5"}