{"id":"openSUSE-SU-2026:21640-1","summary":"Security update for rmt-server","details":"This update for rmt-server fixes the following issues:\n\nUpdate to version 3.1 (bsc#1274715).\n\nSecurity issues fixed:\n\n- CVE-2026-26961: rack: greedy multipart boundary parsing can lead to parser differentials and WAF bypass\n  (bsc#1261398).\n- CVE-2026-26962: rack: improper unfolding of folded multipart headers can lead to downstream header injection and\n  response splitting(bsc#1261471).\n- CVE-2026-34763: rack: unescaped regex interpolation of configured root path can lead to root directory disclosure\n  (bsc#1261406).\n- CVE-2026-34230: rack: crafted `Accept-Encoding` headers can cause a denial of service (bsc#1261388).\n- CVE-2026-34785: rack: prefix matching logic can lead to the exposure of unintended files under the static root\n  (bsc#1261417).\n- CVE-2026-34786: rack: URL-encoded path mismatch can lead to `header_rules` bypass (bsc#1261426).\n- CVE-2026-34826: rack: missing individual byte range limit checks when parsing HTTP `Range` headers can lead to\n  excessive resource consumption and a denial of service (bsc#1261436).\n- CVE-2026-34829: rack: multipart parsing without `Content-Length` header can lead to unbounded chunked file uploads\n  and a denial of service (bsc#1261447).\n- CVE-2026-34230: rack: quadratic complexity when processing of wildcard `Accept-Encoding` headers can lead to a denial\n  of service (bsc#1261388).\n- CVE-2026-34830: rack: improper sanitization of the `X-Accel-Mapping` request header can lead to the exposure of\n  unintended files via `X-Accel-Redirect` (bsc#1261458).\n- CVE-2026-34831: rack: `Content-Length` header and body byte size mismatch when creating error responses can lead to\n  incorrect HTTP response framing (bsc#1261466).\n\nOther updates and bugfixes:\n\n- Version 3.1:\n  * Remove all errors and warnigs due to new Ruby and Ruby on Rails versions\n- Version 2.28:\n  * Set arch to unknown for Rancher based products (jsc#SCC-759)\n  * Fix purge for large amount of systems (bsc#1262706)\n  * Change data type to `MEDIUMTEXT` in profiles table (bsc#1268305)\n  * Remove `proxy_byos` column\n  * Fix race condition when no system matches (bsc#1268301)\n  * Fix race condition for PAYG (bsc#1268149)\n  * Fix race condition to update a system (bsc#1268303)\n- Version 2.27:\n  * Fix ReDoS vulnerability in `Addressable`\n  * Fixes out-of-bounds read vulnerability in `rdiscount`\n","modified":"2026-08-27T18:23:15.391799988Z","published":"2026-08-25T06:34:56Z","related":["CVE-2026-26961","CVE-2026-26962","CVE-2026-34230","CVE-2026-34763","CVE-2026-34785","CVE-2026-34786","CVE-2026-34826","CVE-2026-34829","CVE-2026-34830","CVE-2026-34831"],"upstream":["CVE-2026-26961","CVE-2026-26962","CVE-2026-34230","CVE-2026-34763","CVE-2026-34785","CVE-2026-34786","CVE-2026-34826","CVE-2026-34829","CVE-2026-34830","CVE-2026-34831"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261388"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261398"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261406"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261417"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261426"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261436"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261447"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261458"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261466"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261471"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262706"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268149"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268301"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268303"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268305"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274715"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26961"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26962"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34230"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34763"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34785"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34786"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34826"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34829"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34830"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34831"}],"affected":[{"package":{"name":"rmt-server","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/rmt-server&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server":"3.1.0-160000.1.1","rmt-server-config":"3.1.0-160000.1.1","rmt-server-pubcloud":"3.1.0-160000.1.1","ansible-rmt-server":"3.1.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21640-1.json"}}],"schema_version":"1.9.0"}