{"schema_version":"1.7.5","id":"openSUSE-SU-2026:21448-1","published":"2026-07-27T15:55:38Z","modified":"2026-07-29T18:24:28.648555524Z","related":["CVE-2025-7783","CVE-2026-12143","CVE-2026-13149","CVE-2026-13311","CVE-2026-13676","CVE-2026-27601","CVE-2026-40181","CVE-2026-49356","CVE-2026-53550","CVE-2026-53632","CVE-2026-54466","CVE-2026-54490","CVE-2026-55602"],"upstream":["CVE-2025-7783","CVE-2026-12143","CVE-2026-13149","CVE-2026-13311","CVE-2026-13676","CVE-2026-27601","CVE-2026-40181","CVE-2026-49356","CVE-2026-53550","CVE-2026-53632","CVE-2026-54466","CVE-2026-54490","CVE-2026-55602"],"summary":"Security update for agama-web-ui","details":"This update for agama-web-ui fixes the following issues:\n\n- CVE-2025-7783: form-data: unsafe `Math.random()` function is used to select a boundary value for multipart\n  form-encoded data (bsc#1246822).\n- CVE-2026-12143: form-data: CRLF injection via unescaped multipart field names and filenames (bsc#1272310).\n- CVE-2026-13149: brace-expansion: `expand()` function exhibits exponential-time complexity when processing\n  non-expanding `{}` brace groups (bsc#1269927).\n- CVE-2026-13311: shell-quote: quadratic complexity in `parse()` function when processing specially crafted strings\n  (bsc#1269359).\n- CVE-2026-13676: fast-uri: host-based policy bypass due to failure to canonicalize Unicode/IDN hostnames for\n  HTTP-family URLs (bsc#1269595).\n- CVE-2026-27601: underscore: DoS via stack overflow due to missing depth limits in `_.flatten` and `_.isEqual`\n  functions (bsc#1259169).\n- CVE-2026-40181: react-router: open redirect to an external domain due to path values starting with `//` being\n  reinterpreted as protocol-relative URLs (bsc#1272311).\n- CVE-2026-49356: @babel/core: arbitrary file read via `sourceMappingURL` comment (bsc#1272317).\n- CVE-2026-53550: js-yaml: quadratic complexity in merge-key processing when processing a crafted YAML document\n  (bsc#1268851).\n- CVE-2026-53632: launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows (bsc#1272319).\n- CVE-2026-54466: websocket-driver: message corruption via abuse of protocol length headers (bsc#1272312).\n- CVE-2026-54490: websocket-driver: resource limit bypass via message compression (bsc#1272313).\n- CVE-2026-55602: http-proxy-middleware: Host-header-driven backend routing bypass via `router` host+path substring\n  matching (bsc#1272318).\n","affected":[{"package":{"name":"agama-web-ui","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/agama-web-ui&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17+673.b97ba64d6-160000.12.1"}]}],"ecosystem_specific":{"binaries":[{"agama-web-ui":"17+673.b97ba64d6-160000.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21448-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246822"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259169"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268851"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269359"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269514"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269595"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269927"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272310"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272311"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272312"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272313"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272317"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272318"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272319"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-7783"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12143"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13149"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13311"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13676"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27601"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40181"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-49356"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53550"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53632"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-54466"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-54490"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55602"}]}