OPENSUSE-SU-2026:12045-1
Vulnerability from csaf_opensuse - Published: 2026-10-04 00:00 - Updated: 2026-10-05 09:19Summary
python313-urllib3_1-1.26.20-7.2 on GA media
Severity
Moderate
Notes
Title of the patch: python313-urllib3_1-1.26.20-7.2 on GA media
Description of the patch: These are all security issues fixed in the python313-urllib3_1-1.26.20-7.2 package on the GA media of openSUSE Tumbleweed.
Patchnames: openSUSE-Tumbleweed-2026-12045
Terms of use: CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
Affected products
Recommended
8 products
| Product | Identifier | Version | Remediation |
|---|---|---|---|
| Unresolved product id: openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64 | — |
Vendor Fix
|
Threats
Impact
low
Affected products
Recommended
8 products, the same list as for
CVE-2016-9015
Threats
Impact
moderate
4 (Medium)
Affected products
Recommended
8 products, the same list as for
CVE-2016-9015
Threats
Impact
low
5.4 (Medium)
Affected products
Recommended
8 products, the same list as for
CVE-2016-9015
Threats
Impact
moderate
5.8 (Medium)
Affected products
Recommended
8 products, the same list as for
CVE-2016-9015
Threats
Impact
moderate
7.5 (High)
Affected products
Recommended
8 products, the same list as for
CVE-2016-9015
Threats
Impact
important
5.9 (Medium)
Affected products
Recommended
8 products, the same list as for
CVE-2016-9015
Threats
Impact
moderate
4.2 (Medium)
Affected products
Recommended
8 products, the same list as for
CVE-2016-9015
Threats
Impact
moderate
References
31 references
{
"document": {
"aggregate_severity": {
"namespace": "https://www.suse.com/support/security/rating/",
"text": "moderate"
},
"category": "csaf_security_advisory",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright 2024 SUSE LLC. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "summary",
"text": "python313-urllib3_1-1.26.20-7.2 on GA media",
"title": "Title of the patch"
},
{
"category": "description",
"text": "These are all security issues fixed in the python313-urllib3_1-1.26.20-7.2 package on the GA media of openSUSE Tumbleweed.",
"title": "Description of the patch"
},
{
"category": "details",
"text": "openSUSE-Tumbleweed-2026-12045",
"title": "Patchnames"
},
{
"category": "legal_disclaimer",
"text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
"title": "Terms of use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://www.suse.com/support/security/contact/",
"name": "SUSE Product Security Team",
"namespace": "https://www.suse.com/"
},
"references": [
{
"category": "external",
"summary": "SUSE ratings",
"url": "https://www.suse.com/support/security/rating/"
},
{
"category": "self",
"summary": "URL of this CSAF notice",
"url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_12045-1.json"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2016-9015 page",
"url": "https://www.suse.com/security/cve/CVE-2016-9015/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2018-20060 page",
"url": "https://www.suse.com/security/cve/CVE-2018-20060/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2019-11324 page",
"url": "https://www.suse.com/security/cve/CVE-2019-11324/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2019-9740 page",
"url": "https://www.suse.com/security/cve/CVE-2019-9740/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2020-26137 page",
"url": "https://www.suse.com/security/cve/CVE-2020-26137/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2021-33503 page",
"url": "https://www.suse.com/security/cve/CVE-2021-33503/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2023-43804 page",
"url": "https://www.suse.com/security/cve/CVE-2023-43804/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2023-45803 page",
"url": "https://www.suse.com/security/cve/CVE-2023-45803/"
}
],
"title": "python313-urllib3_1-1.26.20-7.2 on GA media",
"tracking": {
"current_release_date": "2026-10-05T09:19:25Z",
"generator": {
"date": "2026-10-04T00:00:00Z",
"engine": {
"name": "cve-database.git:bin/generate-csaf.pl",
"version": "1"
}
},
"id": "openSUSE-SU-2026:12045-1",
"initial_release_date": "2026-10-04T00:00:00Z",
"revision_history": [
{
"date": "2026-10-04T00:00:00Z",
"number": "1",
"summary": "Current version"
},
{
"date": "2026-10-05T09:19:25Z",
"number": "2",
"summary": "unknown changes"
}
],
"status": "final",
"version": "2"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "python313-urllib3_1-0:1.26.20-7.2.aarch64",
"product": {
"name": "python313-urllib3_1-0:1.26.20-7.2.aarch64",
"product_id": "python313-urllib3_1-0:1.26.20-7.2.aarch64",
"product_identification_helper": {
"cpe": "cpe:2.3:a:python:urllib3:1.26.20:*:*:*:*:*:*:*",
"purl": "pkg:rpm/suse/python313-urllib3_1@1.26.20-7.2?arch=aarch64\u0026upstream=python-urllib3_1-0:1.26.20-7.2.src.rpm"
}
}
},
{
"category": "product_version",
"name": "python314-urllib3_1-0:1.26.20-7.2.aarch64",
"product": {
"name": "python314-urllib3_1-0:1.26.20-7.2.aarch64",
"product_id": "python314-urllib3_1-0:1.26.20-7.2.aarch64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/python314-urllib3_1@1.26.20-7.2?arch=aarch64"
}
}
}
],
"category": "architecture",
"name": "aarch64"
},
{
"branches": [
{
"category": "product_version",
"name": "python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"product": {
"name": "python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"product_id": "python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"product_identification_helper": {
"cpe": "cpe:2.3:a:python:urllib3:1.26.20:*:*:*:*:*:*:*",
"purl": "pkg:rpm/suse/python313-urllib3_1@1.26.20-7.2?arch=ppc64le\u0026upstream=python-urllib3_1-0:1.26.20-7.2.src.rpm"
}
}
},
{
"category": "product_version",
"name": "python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"product": {
"name": "python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"product_id": "python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"product_identification_helper": {
"purl": "pkg:rpm/suse/python314-urllib3_1@1.26.20-7.2?arch=ppc64le"
}
}
}
],
"category": "architecture",
"name": "ppc64le"
},
{
"branches": [
{
"category": "product_version",
"name": "python313-urllib3_1-0:1.26.20-7.2.s390x",
"product": {
"name": "python313-urllib3_1-0:1.26.20-7.2.s390x",
"product_id": "python313-urllib3_1-0:1.26.20-7.2.s390x",
"product_identification_helper": {
"cpe": "cpe:2.3:a:python:urllib3:1.26.20:*:*:*:*:*:*:*",
"purl": "pkg:rpm/suse/python313-urllib3_1@1.26.20-7.2?arch=s390x\u0026upstream=python-urllib3_1-0:1.26.20-7.2.src.rpm"
}
}
},
{
"category": "product_version",
"name": "python314-urllib3_1-0:1.26.20-7.2.s390x",
"product": {
"name": "python314-urllib3_1-0:1.26.20-7.2.s390x",
"product_id": "python314-urllib3_1-0:1.26.20-7.2.s390x",
"product_identification_helper": {
"purl": "pkg:rpm/suse/python314-urllib3_1@1.26.20-7.2?arch=s390x"
}
}
}
],
"category": "architecture",
"name": "s390x"
},
{
"branches": [
{
"category": "product_version",
"name": "python313-urllib3_1-0:1.26.20-7.2.x86_64",
"product": {
"name": "python313-urllib3_1-0:1.26.20-7.2.x86_64",
"product_id": "python313-urllib3_1-0:1.26.20-7.2.x86_64",
"product_identification_helper": {
"cpe": "cpe:2.3:a:python:urllib3:1.26.20:*:*:*:*:*:*:*",
"purl": "pkg:rpm/suse/python313-urllib3_1@1.26.20-7.2?arch=x86_64\u0026upstream=python-urllib3_1-0:1.26.20-7.2.src.rpm"
}
}
},
{
"category": "product_version",
"name": "python314-urllib3_1-0:1.26.20-7.2.x86_64",
"product": {
"name": "python314-urllib3_1-0:1.26.20-7.2.x86_64",
"product_id": "python314-urllib3_1-0:1.26.20-7.2.x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/python314-urllib3_1@1.26.20-7.2?arch=x86_64"
}
}
}
],
"category": "architecture",
"name": "x86_64"
},
{
"branches": [
{
"category": "product_name",
"name": "openSUSE Tumbleweed",
"product": {
"name": "openSUSE Tumbleweed",
"product_id": "openSUSE Tumbleweed",
"product_identification_helper": {
"cpe": "cpe:/o:opensuse:tumbleweed"
}
}
}
],
"category": "product_family",
"name": "SUSE Linux Enterprise"
}
],
"category": "vendor",
"name": "SUSE"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "python313-urllib3_1-0:1.26.20-7.2.aarch64 as component of openSUSE Tumbleweed",
"product_id": "openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64"
},
"product_reference": "python313-urllib3_1-0:1.26.20-7.2.aarch64",
"relates_to_product_reference": "openSUSE Tumbleweed"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "python313-urllib3_1-0:1.26.20-7.2.ppc64le as component of openSUSE Tumbleweed",
"product_id": "openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le"
},
"product_reference": "python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"relates_to_product_reference": "openSUSE Tumbleweed"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "python313-urllib3_1-0:1.26.20-7.2.s390x as component of openSUSE Tumbleweed",
"product_id": "openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x"
},
"product_reference": "python313-urllib3_1-0:1.26.20-7.2.s390x",
"relates_to_product_reference": "openSUSE Tumbleweed"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "python313-urllib3_1-0:1.26.20-7.2.x86_64 as component of openSUSE Tumbleweed",
"product_id": "openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64"
},
"product_reference": "python313-urllib3_1-0:1.26.20-7.2.x86_64",
"relates_to_product_reference": "openSUSE Tumbleweed"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "python314-urllib3_1-0:1.26.20-7.2.aarch64 as component of openSUSE Tumbleweed",
"product_id": "openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64"
},
"product_reference": "python314-urllib3_1-0:1.26.20-7.2.aarch64",
"relates_to_product_reference": "openSUSE Tumbleweed"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "python314-urllib3_1-0:1.26.20-7.2.ppc64le as component of openSUSE Tumbleweed",
"product_id": "openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le"
},
"product_reference": "python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"relates_to_product_reference": "openSUSE Tumbleweed"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "python314-urllib3_1-0:1.26.20-7.2.s390x as component of openSUSE Tumbleweed",
"product_id": "openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x"
},
"product_reference": "python314-urllib3_1-0:1.26.20-7.2.s390x",
"relates_to_product_reference": "openSUSE Tumbleweed"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "python314-urllib3_1-0:1.26.20-7.2.x86_64 as component of openSUSE Tumbleweed",
"product_id": "openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
},
"product_reference": "python314-urllib3_1-0:1.26.20-7.2.x86_64",
"relates_to_product_reference": "openSUSE Tumbleweed"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2016-9015",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2016-9015"
}
],
"notes": [
{
"category": "general",
"text": "Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk of man-in-the-middle and information leakage attacks. This vulnerability affects users using versions 1.17 and 1.18 of the urllib3 library, who are using the optional PyOpenSSL support for TLS instead of the regular standard library TLS backend, and who are using OpenSSL 1.1.0 via PyOpenSSL. This is an extremely uncommon configuration, so the security impact of this vulnerability is low.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2016-9015",
"url": "https://www.suse.com/security/cve/CVE-2016-9015"
},
{
"category": "external",
"summary": "SUSE Bug 1023502 for CVE-2016-9015",
"url": "https://bugzilla.suse.com/1023502"
},
{
"category": "external",
"summary": "SUSE Bug 1024540 for CVE-2016-9015",
"url": "https://bugzilla.suse.com/1024540"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-04T00:00:00Z",
"details": "low"
}
],
"title": "CVE-2016-9015"
},
{
"cve": "CVE-2018-20060",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2018-20060"
}
],
"notes": [
{
"category": "general",
"text": "urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2018-20060",
"url": "https://www.suse.com/security/cve/CVE-2018-20060"
},
{
"category": "external",
"summary": "SUSE Bug 1119376 for CVE-2018-20060",
"url": "https://bugzilla.suse.com/1119376"
},
{
"category": "external",
"summary": "SUSE Bug 1216275 for CVE-2018-20060",
"url": "https://bugzilla.suse.com/1216275"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 2.6,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N",
"version": "3.0"
},
"products": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-04T00:00:00Z",
"details": "moderate"
}
],
"title": "CVE-2018-20060"
},
{
"cve": "CVE-2019-11324",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2019-11324"
}
],
"notes": [
{
"category": "general",
"text": "The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2019-11324",
"url": "https://www.suse.com/security/cve/CVE-2019-11324"
},
{
"category": "external",
"summary": "SUSE Bug 1132900 for CVE-2019-11324",
"url": "https://bugzilla.suse.com/1132900"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.0"
},
"products": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-04T00:00:00Z",
"details": "low"
}
],
"title": "CVE-2019-11324"
},
{
"cve": "CVE-2019-9740",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2019-9740"
}
],
"notes": [
{
"category": "general",
"text": "An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \\r\\n (specifically in the query string after a ? character) followed by an HTTP header or a Redis command. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2019-9740",
"url": "https://www.suse.com/security/cve/CVE-2019-9740"
},
{
"category": "external",
"summary": "SUSE Bug 1129071 for CVE-2019-9740",
"url": "https://bugzilla.suse.com/1129071"
},
{
"category": "external",
"summary": "SUSE Bug 1130840 for CVE-2019-9740",
"url": "https://bugzilla.suse.com/1130840"
},
{
"category": "external",
"summary": "SUSE Bug 1132663 for CVE-2019-9740",
"url": "https://bugzilla.suse.com/1132663"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.0"
},
"products": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-04T00:00:00Z",
"details": "moderate"
}
],
"title": "CVE-2019-9740"
},
{
"cve": "CVE-2020-26137",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2020-26137"
}
],
"notes": [
{
"category": "general",
"text": "urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2020-26137",
"url": "https://www.suse.com/security/cve/CVE-2020-26137"
},
{
"category": "external",
"summary": "SUSE Bug 1177120 for CVE-2020-26137",
"url": "https://bugzilla.suse.com/1177120"
},
{
"category": "external",
"summary": "SUSE Bug 1177211 for CVE-2020-26137",
"url": "https://bugzilla.suse.com/1177211"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-04T00:00:00Z",
"details": "moderate"
}
],
"title": "CVE-2020-26137"
},
{
"cve": "CVE-2021-33503",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2021-33503"
}
],
"notes": [
{
"category": "general",
"text": "An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2021-33503",
"url": "https://www.suse.com/security/cve/CVE-2021-33503"
},
{
"category": "external",
"summary": "SUSE Bug 1187045 for CVE-2021-33503",
"url": "https://bugzilla.suse.com/1187045"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-04T00:00:00Z",
"details": "important"
}
],
"title": "CVE-2021-33503"
},
{
"cve": "CVE-2023-43804",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2023-43804"
}
],
"notes": [
{
"category": "general",
"text": "urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn\u0027t treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn\u0027t disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2023-43804",
"url": "https://www.suse.com/security/cve/CVE-2023-43804"
},
{
"category": "external",
"summary": "SUSE Bug 1215968 for CVE-2023-43804",
"url": "https://bugzilla.suse.com/1215968"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-04T00:00:00Z",
"details": "moderate"
}
],
"title": "CVE-2023-43804"
},
{
"cve": "CVE-2023-45803",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2023-45803"
}
],
"notes": [
{
"category": "general",
"text": "urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn\u0027t remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although this behavior is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers. Because the vulnerability requires a previously trusted service to become compromised in order to have an impact on confidentiality we believe the exploitability of this vulnerability is low. Additionally, many users aren\u0027t putting sensitive data in HTTP request bodies, if this is the case then this vulnerability isn\u0027t exploitable. Both of the following conditions must be true to be affected by this vulnerability: 1. Using urllib3 and submitting sensitive information in the HTTP request body (such as form data or JSON) and 2. The origin service is compromised and starts redirecting using 301, 302, or 303 to a malicious peer or the redirected-to service becomes compromised. This issue has been addressed in versions 1.26.18 and 2.0.7 and users are advised to update to resolve this issue. Users unable to update should disable redirects for services that aren\u0027t expecting to respond with redirects with `redirects=False` and disable automatic redirects with `redirects=False` and handle 301, 302, and 303 redirects manually by stripping the HTTP request body.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2023-45803",
"url": "https://www.suse.com/security/cve/CVE-2023-45803"
},
{
"category": "external",
"summary": "SUSE Bug 1216377 for CVE-2023-45803",
"url": "https://bugzilla.suse.com/1216377"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.2,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python313-urllib3_1-0:1.26.20-7.2.x86_64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.aarch64",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.ppc64le",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.s390x",
"openSUSE Tumbleweed:python314-urllib3_1-0:1.26.20-7.2.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-04T00:00:00Z",
"details": "moderate"
}
],
"title": "CVE-2023-45803"
}
]
}
Loading…
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…