{"id":"SUSE-SU-2026:1220-1","summary":"Security update for python-poetry","details":"This update for python-poetry fixes the following issue:\n\n- CVE-2026-34591: From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary file write (bsc#1261383).\n","modified":"2026-07-13T14:00:33.802732770Z","published":"2026-04-08T16:03:04Z","withdrawn":"2026-07-13T14:00:33.802732500Z","related":["CVE-2026-34591"],"upstream":["CVE-2026-34591"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261220-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261383"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34591"}],"schema_version":"1.7.5"}