Security update for cockpit
This update for cockpit fixes the following issues - CVE-2026-4802: remote command execution via unsanitized user-controlled parameters within crafted links in system logs UI (bsc#1265040). - CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive CPU and memory consumption and may crash a Node.js process (bsc#1257838). - CVE-2026-27606: rollup: Arbitrary File Write via Path Traversal in Rollup 4 (bsc#1258900). - CVE-2026-27904: minimatch: nested *() extglobs can lead to regular expressions with exponential backtracking complexity and a ReDoS (bsc#1259015).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for cockpit fixes the following issues - CVE-2026-4802: remote command execution via unsanitized user-controlled parameters within crafted links in system logs UI (bsc#1265040). - CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive CPU and memory consumption and may crash a Node.js process (bsc#1257838). - CVE-2026-27606: rollup: Arbitrary File Write via Path Traversal in Rollup 4 (bsc#1258900). - CVE-2026-27904: minimatch: nested *() extglobs can lead to regular expressions with exponential backtracking complexity and a ReDoS (bsc#1259015).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1257838
- https://bugzilla.suse.com/1258900
- https://bugzilla.suse.com/1259015
- https://bugzilla.suse.com/1265040
- https://www.suse.com/security/cve/CVE-2026-25547
- https://www.suse.com/security/cve/CVE-2026-27606
- https://www.suse.com/security/cve/CVE-2026-27904
- https://www.suse.com/security/cve/CVE-2026-4802
- https://www.suse.com/support/update/announcement/2026/suse-su-20262363-1/