OPENSUSE-SU-2026:20502-1

Advisory lineage Upstream: 2 Downstream: 0
Published: 10 Apr 2026, 11:33
Last modified:22 Apr 2026, 18:26

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Apr 2026, 11:33
Published
Vulnerability first disclosed
22 Apr 2026, 18:26
Last Modified
Vulnerability information updated

Description

Security update for cockpit-podman This update for cockpit-podman fixes the following issues: - CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive CPU and memory consumption and may crash a Node.js process (bsc#1257836). - CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character that doesn't appear in the test string (bsc#1258641).

Affected Systems

  • opensusecockpit-podman&distro=openSUSE Leap 16.0

    < 117-160000.2.1

References (4)