{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20918-1","published":"2026-06-08T09:30:18Z","modified":"2026-06-10T18:24:16.243159711Z","related":["CVE-2026-31958"],"upstream":["CVE-2026-31958"],"summary":"Security update for salt","details":"This update for salt fixes the following issues:\n\nSecurity fixes:\n\n- CVE-2026-31958: python-tornado: parsing large multipart bodies with many parts can cause a denial of service (bsc#1259554)\n\nOther changes in salt:\n\n- Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700)\n- Harden Tornado from invalid HTTP reason phrases\n- Read full URI from ldap pillar config (bsc#1254900)\n- Make users with backslash working for salt-ssh (bsc#1254629)\n- Fixed ansible.playbooks extra-vars quoting (bsc#1257831)\n- Fixed virtualenv call in test helper to use proper python version\n\n","affected":[{"package":{"name":"salt","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/salt&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3006.0-160000.5.1"}]}],"ecosystem_specific":{"binaries":[{"python313-salt":"3006.0-160000.5.1","python313-salt-testsuite":"3006.0-160000.5.1","salt":"3006.0-160000.5.1","salt-api":"3006.0-160000.5.1","salt-bash-completion":"3006.0-160000.5.1","salt-cloud":"3006.0-160000.5.1","salt-doc":"3006.0-160000.5.1","salt-fish-completion":"3006.0-160000.5.1","salt-master":"3006.0-160000.5.1","salt-minion":"3006.0-160000.5.1","salt-proxy":"3006.0-160000.5.1","salt-ssh":"3006.0-160000.5.1","salt-standalone-formulas-configuration":"3006.0-160000.5.1","salt-syndic":"3006.0-160000.5.1","salt-transactional-update":"3006.0-160000.5.1","salt-zsh-completion":"3006.0-160000.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20918-1.json"}},{"package":{"name":"salt-test","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/salt-test&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3006.0-160000.5.1"}]}],"ecosystem_specific":{"binaries":[{"python313-salt":"3006.0-160000.5.1","python313-salt-testsuite":"3006.0-160000.5.1","salt":"3006.0-160000.5.1","salt-api":"3006.0-160000.5.1","salt-bash-completion":"3006.0-160000.5.1","salt-cloud":"3006.0-160000.5.1","salt-doc":"3006.0-160000.5.1","salt-fish-completion":"3006.0-160000.5.1","salt-master":"3006.0-160000.5.1","salt-minion":"3006.0-160000.5.1","salt-proxy":"3006.0-160000.5.1","salt-ssh":"3006.0-160000.5.1","salt-standalone-formulas-configuration":"3006.0-160000.5.1","salt-syndic":"3006.0-160000.5.1","salt-transactional-update":"3006.0-160000.5.1","salt-zsh-completion":"3006.0-160000.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20918-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254629"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254900"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257583"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257831"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259554"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259700"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31958"}]}