FlawAtlas
Search the atlas
SUSE-SU-2026:0642-1 Not scored

Security update for python313

This update for python313 fixes the following issues: Update to Python 3.13.12 - CVE-2026-0672: Fixed a HTTP header injection via user-controlled cookie values and parameters when using http.cookies.Morsel. (bsc#1257031) - CVE-2026-0865: Fixed a bug where a user-controlled header containing newlines can allow injecting HTTP headers. (bsc#1257042) - CVE-2025-15282: Fixed a bug where a user-controlled data URLs parsed may allow injecting headers. (bsc#1257046) - CVE-2025-11468: Fixed a header injection when folding a long comment in an email header containing exclusively unfoldable characters. (bsc#1257029) - CVE-2026-1299: Fixed header injection when an email is serialized due to improper newline quoting in `BytesGenerator`: Fixed a header injection when folding a long comment in an email header containing exclusively unfoldable characters. (bsc#1257029)

Exploit probability Not scored
Published February 26, 2026
Required by Not available
Last source change February 26, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for Python 3 15 SP7 python313
SUSE:Linux Enterprise Module for Python 3 15 SP7 python313-core

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:0642-1

This update for python313 fixes the following issues: Update to Python 3.13.12 - CVE-2026-0672: Fixed a HTTP header injection via user-controlled cookie values and parameters when using http.cookies.Morsel. (bsc#1257031) - CVE-2026-0865: Fixed a bug where a user-controlled header containing newlines can allow injecting HTTP headers. (bsc#1257042) - CVE-2025-15282: Fixed a bug where a user-controlled data URLs parsed may allow injecting headers. (bsc#1257046) - CVE-2025-11468: Fixed a header injection when folding a long comment in an email header containing exclusively unfoldable characters. (bsc#1257029) - CVE-2026-1299: Fixed header injection when an email is serialized due to improper newline quoting in `BytesGenerator`: Fixed a header injection when folding a long comment in an email header containing exclusively unfoldable characters. (bsc#1257029)

View original source

05 / REFERENCES

Further evidence