FlawAtlas
Search the atlas
OPENSUSE-SU-2026:20412-1 Not scored

Security update for salt

This update for salt fixes the following issues: Changes in salt: - Security issues fixed: * CVE-2025-67724: fixed missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: fixed DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: fixed HTTP header parameter parsing algorithm (bsc#1254904) - Fixed KeyError in postgres module with PostgreSQL 17 (bsc#1254325) - Use internal deb classes instead of external aptsource lib - Improved performance of wheel key.finger call (bsc#1240532) - Improved performance of utils.find_json function (bsc#1246130) - Extend warn_until period to 2027

Exploit probability Not scored
Published March 24, 2026
Required by Not available
Last source change March 29, 2026

02 / AFFECTED SOFTWARE

Affected packages

openSUSE:Leap 16.0 salt
openSUSE:Leap 16.0 salt-test

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities openSUSE-SU-2026:20412-1

This update for salt fixes the following issues: Changes in salt: - Security issues fixed: * CVE-2025-67724: fixed missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: fixed DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: fixed HTTP header parameter parsing algorithm (bsc#1254904) - Fixed KeyError in postgres module with PostgreSQL 17 (bsc#1254325) - Use internal deb classes instead of external aptsource lib - Improved performance of wheel key.finger call (bsc#1240532) - Improved performance of utils.find_json function (bsc#1246130) - Extend warn_until period to 2027

View original source

05 / REFERENCES

Further evidence