gpp_maybe
Security update for python3
SUSE-SLE-Module-Development-Tools-15-SP7-2026-664
This update for python3 fixes the following issues: - CVE-2025-11468: header injection when folding a long comment in an email header containing exclusively unfoldable characters (bsc#1257029). - CVE-2026-0672: HTTP header injection via user-controlled cookie values and parameters when using http.cookies.Morsel (bsc#1257031). - CVE-2026-0865: user-controlled header containing newlines can allow injecting HTTP headers (bsc#1257042). - CVE-2025-15366: user-controlled command can allow additional commands injected using newlines (bsc#1257044). - CVE-2025-15282: user-controlled data URLs parsed may allow injecting headers (bsc#1257046). - CVE-2025-15367: control characters may allow the injection of additional commands (bsc#1257041).
-
Release DateFeb 26 2026
-
ReferencesBugzilla: 1257029, 1257031, 1257046, 1257041, 1257044, 1257042
CVEs: CVE-2025-15282, CVE-2026-0672, CVE-2025-15366, CVE-2025-15367, CVE-2026-0865, CVE-2025-11468 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Development Tools Module 15.7 s390x
-
Packagespython3-core
Python 3 Interpreterpython3-tools3.6.15-150300.10.106.1 lock src
Python Utility and Demonstration Scripts3.6.15-150300.10.106.1 lock rpm
Development Tools Module 15.7 ppc64le
-
Packagespython3-core
Python 3 Interpreterpython3-tools3.6.15-150300.10.106.1 lock src
Python Utility and Demonstration Scripts3.6.15-150300.10.106.1 lock rpm
Development Tools Module 15.7 aarch64
-
Packagespython3-core
Python 3 Interpreterpython3-tools3.6.15-150300.10.106.1 lock src
Python Utility and Demonstration Scripts3.6.15-150300.10.106.1 lock rpm
Development Tools Module 15.7 x86_64
-
Packagespython3-core
Python 3 Interpreterpython3-tools3.6.15-150300.10.106.1 lock src
Python Utility and Demonstration Scripts3.6.15-150300.10.106.1 lock rpm