OPENSUSE-SU-2026:20502-1
Advisory lineage Upstream: 2 Downstream: 0
Upstream
Published: 10 Apr 2026, 11:33
Last modified:22 Apr 2026, 18:26
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
10 Apr 2026, 11:33
Published
Vulnerability first disclosed
22 Apr 2026, 18:26
Last Modified
Vulnerability information updated
Description
Security update for cockpit-podman This update for cockpit-podman fixes the following issues: - CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive CPU and memory consumption and may crash a Node.js process (bsc#1257836). - CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character that doesn't appear in the test string (bsc#1258641).
Affected Systems
- opensuse•cockpit-podman&distro=openSUSE Leap 16.0
< 117-160000.2.1