Security update for python311
This update for python311 fixes the following issues: - CVE-2025-11468: preserving parens when folding comments in email headers. (bsc#1257029) - CVE-2026-0672: rejects control characters in http cookies. (bsc#1257031) - CVE-2026-0865: rejecting control characters in wsgiref.headers.Headers, which could be abused for injecting false HTTP headers. (bsc#1257042) - CVE-2025-15366: basically the same as the previous patch for IMAP protocol. (bsc#1257044) - CVE-2025-15282: basically the same as the previous patch for urllib library. (bsc#1257046) - CVE-2025-15367: basically the same as the previous patch for poplib library. (bsc#1257041) - CVE-2025-12781: fix decoding with non-standard Base64 alphabet (bsc#1257108)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for python311 fixes the following issues: - CVE-2025-11468: preserving parens when folding comments in email headers. (bsc#1257029) - CVE-2026-0672: rejects control characters in http cookies. (bsc#1257031) - CVE-2026-0865: rejecting control characters in wsgiref.headers.Headers, which could be abused for injecting false HTTP headers. (bsc#1257042) - CVE-2025-15366: basically the same as the previous patch for IMAP protocol. (bsc#1257044) - CVE-2025-15282: basically the same as the previous patch for urllib library. (bsc#1257046) - CVE-2025-15367: basically the same as the previous patch for poplib library. (bsc#1257041) - CVE-2025-12781: fix decoding with non-standard Base64 alphabet (bsc#1257108)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1257029
- https://bugzilla.suse.com/1257031
- https://bugzilla.suse.com/1257041
- https://bugzilla.suse.com/1257042
- https://bugzilla.suse.com/1257044
- https://bugzilla.suse.com/1257046
- https://bugzilla.suse.com/1257108
- https://www.suse.com/security/cve/CVE-2025-11468
- https://www.suse.com/security/cve/CVE-2025-12781
- https://www.suse.com/security/cve/CVE-2025-15282
- https://www.suse.com/security/cve/CVE-2025-15366
- https://www.suse.com/security/cve/CVE-2025-15367
- https://www.suse.com/security/cve/CVE-2026-0672
- https://www.suse.com/security/cve/CVE-2026-0865
- https://www.suse.com/support/update/announcement/2026/suse-su-202620710-1/