shield Security update for python-python-dotenv
SUSE-SLES-16.0-918


This update for python-python-dotenv fixes the following issue: - CVE-2026-28684: Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink (bsc#1262423).

  • Release Date
    Jun 11 2026
  • References
    Bugzilla: 1262423
    CVEs: CVE-2026-28684
  • Type
    security
  • Severity
    moderate

cloud_download Downloads

SUSE Linux Enterprise Server 16.0 x86_64
SUSE Linux Enterprise Server 16.0 aarch64
SUSE Linux Enterprise Server 16.0 ppc64le
SUSE Linux Enterprise Server 16.0 s390x
SUSE Linux Enterprise Server for SAP applications 16.0 ppc64le
SUSE Linux Enterprise Server for SAP applications 16.0 x86_64