{"id":"SUSE-SU-2026:4411-1","summary":"Security update for python","details":"This update for python fixes the following issues:\n\n- CVE-2026-6879: quadratic behavior in `xml.etree.ElementPath` index predicates can lead to a denial of service via high\n  CPU usage (bsc#1273148).\n- CVE-2026-9669: crafted input can cause a stack buffer overflow (bsc#1267974).\n- CVE-2026-15806: urllib.request.HTTPPasswordMgr credentials for one URL scheme sent over another scheme (bsc#1276223).\n- CVE-2026-17084: StringPrep algorithm considered Unicode codepoint attributes outside Unicode 3.2.0 (bsc#1276226).\n- CVE-2026-18503: attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect\n  sniffing and consume significant CPU (bsc#1274683).\n- CVE-2026-19672: The tarfile module's tar and data extraction filters created directories outside the destination for\n  members whose name leaves the destination and retu (bsc#1276227).\n\nChanges for python:\n\n- Update bundled setuptools wheels to setuptools-40.6.2-py2.py3-none-any.whl (bsc#1276903)\n","modified":"2026-10-02T11:30:04.071737814Z","published":"2026-10-01T15:38:59Z","related":["CVE-2026-15806","CVE-2026-17084","CVE-2026-18503","CVE-2026-19672","CVE-2026-6879","CVE-2026-9669"],"upstream":["CVE-2026-15806","CVE-2026-17084","CVE-2026-18503","CVE-2026-19672","CVE-2026-6879","CVE-2026-9669"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264411-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267974"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273148"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274683"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276223"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276226"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276227"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276903"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15806"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-17084"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-18503"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-19672"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6879"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9669"}],"affected":[{"package":{"name":"python","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/python&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.18-150000.133.1"}]}],"ecosystem_specific":{"binaries":[{"python-base":"2.7.18-150000.133.1","python-curses":"2.7.18-150000.133.1","python-gdbm":"2.7.18-150000.133.1","python-xml":"2.7.18-150000.133.1","libpython2_7-1_0":"2.7.18-150000.133.1","python":"2.7.18-150000.133.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4411-1.json"}},{"package":{"name":"python-base","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/python-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.18-150000.133.1"}]}],"ecosystem_specific":{"binaries":[{"python-base":"2.7.18-150000.133.1","python-curses":"2.7.18-150000.133.1","python-gdbm":"2.7.18-150000.133.1","python-xml":"2.7.18-150000.133.1","libpython2_7-1_0":"2.7.18-150000.133.1","python":"2.7.18-150000.133.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4411-1.json"}}],"schema_version":"1.9.0"}