[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:21399-1":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T11:35:27.363Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":26,"duplicates":27,"related":28,"reserved_at":9,"published_at":35,"modified_at":36,"state":9,"summary":37,"references_raw":39,"kevs":135,"epss":9,"epss_history":136,"metrics":137,"affected":138},"OPENSUSE-SU-2026:21399-1","Security update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions\n\nThis update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2025-13465: lodash: prototype pollution in the _.unset and _.omit functions can lead to deletion of methods from\n  global prototypes (bsc#1257325).\n- CVE-2026-4631: SSH command-line argument injection can lead to unauthenticated remote code execution (bsc#1261829).\n- CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive CPU and memory consumption and\n  may crash a Node.js process (bsc#1257836 bsc#1257838 bsc#1257840).\n- CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character\n  that doesn't appear in the test string (bsc#1258637 bsc#1258640 bsc#1258641).\n- CVE-2026-27904: minimatch: nested *() extglobs can lead to regular expressions with exponential backtracking\n  complexity and a ReDoS (bsc#1259010 bsc#1259013 bsc#1259015).\n\nNon security issues fixed:\n\n- cockpit webUI - 'Software updates - install all updates' got an unexpected internal error (bsc#1259210).\n- cockpit-machines does not work out of the box, missing libvirt daemon (bsc#1236149).\n\nChanges for cockpit:\n\n- Update to 364.\n\n- Update to 361 (jsc#PED-15706/jsc#CPT-183):\n\n * Remove all \"Mount\" actions in Anaconda mode\n * Dependency updates\n\n- Update to 360:\n * ws: be more explicit when handling hostnames on cli bsc#1261829/CVE-2026-4631\n * ws: support loading a custom login page\n\n- Update to 358:\n\n * Networking: Add Wi-Fi support\n * Cockpit Client updated to GTK 4\n * Bugfixes and translation updates\n\n- Update to 357:\n\n * lib: Use browser context menu on shift\n * bridge: support Python 3.14 on old kernels (RHEL 8)\n\n- Update to 356:\n\n * systemd: Allow editing timers created by Cockpit\n * Convert license headers to SPDX format\n\n- Update to 355:\n\n * ws: Remove obsolete pam_cockpit_cert module\n * shell: add StartTransientUnit as a sudo alternative\n\nChanges for cockpit-machines:\n\n- Update to 354.\n\n- Update to 352:\n\n - Improvements to the \"Add disk\" and \"Create Volume\" dialogs.\n\n- Update suse_version requirement to function with the planned bump (jsc#PED-15820).\n- Drop explict dependency on libvirt (bsc#1258040, bsc#1236149).\n\n- Update to 348:\n\n * Translation updates\n * Convert license headers to SPDX format\n * Now requires cockpit-devel 356 due to the replacement of xterm/addon-canvas with xterm/addon-webgl\n\n- Update to 347:\n * Bug fixes and translation updates\n\n- Fix esbuild for ppc64le (bsc#1257698).\n\nChanges for cockpit-packages:\n\n- Update to version 5:\n\n * Support transactional systems\n * Improve error/success messages\n * Translation updates\n\n- Patch esbuild to use native runtime on ppc64 (bsc#1257698).\n\nChanges for cockpit-podman:\n\n- Update to 128.\n- Fix esbuild for ppc64le (bsc#1257698).\n\nChanges for cockpit-repos:\n\n- Update to 4.8.\n- Patch esbuild to use native runtime on ppc64 (bsc#1257698).\n\nChanges for cockpit-subscriptions:\n\n- Update to version 16.2 (bsc#1257033).\n- Patch esbuild to use native runtime on ppc64 (bsc#1257698).\n",null,[],[],[],[14,16,18,20,22,24],{"_key":15},"CVE-2025-13465",{"_key":17},"CVE-2026-25547",{"_key":19},"CVE-2026-26996",{"_key":21},"CVE-2026-27904",{"_key":23},"CVE-2026-4631",{"_key":25},"CVE-2026-4802",[],[],[29,30,31,32,33,34],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},"2026-07-21T15:45:48Z","2026-07-24T18:24:25.081526809Z",{"cisa_kev":38,"cisa_ransomware":38,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[40,46,50,54,58,62,66,70,74,78,82,86,90,94,98,102,106,110,115,119,123,127,131],{"url":41,"sources":42,"tags":44},"https://bugzilla.suse.com/1236149",[43],"osv_opensuse",[45],"REPORT",{"url":47,"sources":48,"tags":49},"https://bugzilla.suse.com/1257033",[43],[45],{"url":51,"sources":52,"tags":53},"https://bugzilla.suse.com/1257325",[43],[45],{"url":55,"sources":56,"tags":57},"https://bugzilla.suse.com/1257698",[43],[45],{"url":59,"sources":60,"tags":61},"https://bugzilla.suse.com/1257836",[43],[45],{"url":63,"sources":64,"tags":65},"https://bugzilla.suse.com/1257838",[43],[45],{"url":67,"sources":68,"tags":69},"https://bugzilla.suse.com/1257840",[43],[45],{"url":71,"sources":72,"tags":73},"https://bugzilla.suse.com/1258040",[43],[45],{"url":75,"sources":76,"tags":77},"https://bugzilla.suse.com/1258637",[43],[45],{"url":79,"sources":80,"tags":81},"https://bugzilla.suse.com/1258640",[43],[45],{"url":83,"sources":84,"tags":85},"https://bugzilla.suse.com/1258641",[43],[45],{"url":87,"sources":88,"tags":89},"https://bugzilla.suse.com/1259010",[43],[45],{"url":91,"sources":92,"tags":93},"https://bugzilla.suse.com/1259013",[43],[45],{"url":95,"sources":96,"tags":97},"https://bugzilla.suse.com/1259015",[43],[45],{"url":99,"sources":100,"tags":101},"https://bugzilla.suse.com/1259210",[43],[45],{"url":103,"sources":104,"tags":105},"https://bugzilla.suse.com/1259774",[43],[45],{"url":107,"sources":108,"tags":109},"https://bugzilla.suse.com/1261829",[43],[45],{"url":111,"sources":112,"tags":113},"https://www.suse.com/security/cve/CVE-2025-13465",[43],[114],"WEB",{"url":116,"sources":117,"tags":118},"https://www.suse.com/security/cve/CVE-2026-25547",[43],[114],{"url":120,"sources":121,"tags":122},"https://www.suse.com/security/cve/CVE-2026-26996",[43],[114],{"url":124,"sources":125,"tags":126},"https://www.suse.com/security/cve/CVE-2026-27904",[43],[114],{"url":128,"sources":129,"tags":130},"https://www.suse.com/security/cve/CVE-2026-4631",[43],[114],{"url":132,"sources":133,"tags":134},"https://www.suse.com/security/cve/CVE-2026-4802",[43],[114],[],[],[],[139,152,159,166,173,180],{"ecosystem":140,"name":141,"vendor":142,"product":143,"cpe_part":9,"purl_type":144,"purl_namespace":142,"purl_name":143,"source":9,"versions":145},"openSUSE","cockpit-machines","opensuse","cockpit-machines&distro=openSUSE Leap 16.0","rpm",[146],{"version":147,"is_range":148,"range_type":149,"version_start":9,"version_start_type":9,"version_end":150,"version_end_type":151,"fixed_in":9},"lt354_160000_1_1",true,"ecosystem","354-160000.1.1","excluding",{"ecosystem":140,"name":153,"vendor":142,"product":154,"cpe_part":9,"purl_type":144,"purl_namespace":142,"purl_name":154,"source":9,"versions":155},"cockpit-packages","cockpit-packages&distro=openSUSE Leap 16.0",[156],{"version":157,"is_range":148,"range_type":149,"version_start":9,"version_start_type":9,"version_end":158,"version_end_type":151,"fixed_in":9},"lt5_160000_1_1","5-160000.1.1",{"ecosystem":140,"name":160,"vendor":142,"product":161,"cpe_part":9,"purl_type":144,"purl_namespace":142,"purl_name":161,"source":9,"versions":162},"cockpit-podman","cockpit-podman&distro=openSUSE Leap 16.0",[163],{"version":164,"is_range":148,"range_type":149,"version_start":9,"version_start_type":9,"version_end":165,"version_end_type":151,"fixed_in":9},"lt128_160000_1_1","128-160000.1.1",{"ecosystem":140,"name":167,"vendor":142,"product":168,"cpe_part":9,"purl_type":144,"purl_namespace":142,"purl_name":168,"source":9,"versions":169},"cockpit-repos","cockpit-repos&distro=openSUSE Leap 16.0",[170],{"version":171,"is_range":148,"range_type":149,"version_start":9,"version_start_type":9,"version_end":172,"version_end_type":151,"fixed_in":9},"lt4_8_160000_1_1","4.8-160000.1.1",{"ecosystem":140,"name":174,"vendor":142,"product":175,"cpe_part":9,"purl_type":144,"purl_namespace":142,"purl_name":175,"source":9,"versions":176},"cockpit-subscriptions","cockpit-subscriptions&distro=openSUSE Leap 16.0",[177],{"version":178,"is_range":148,"range_type":149,"version_start":9,"version_start_type":9,"version_end":179,"version_end_type":151,"fixed_in":9},"lt16_2_160000_1_1","16.2-160000.1.1",{"ecosystem":140,"name":181,"vendor":142,"product":182,"cpe_part":9,"purl_type":144,"purl_namespace":142,"purl_name":182,"source":9,"versions":183},"cockpit","cockpit&distro=openSUSE Leap 16.0",[184],{"version":185,"is_range":148,"range_type":149,"version_start":9,"version_start_type":9,"version_end":186,"version_end_type":151,"fixed_in":9},"lt364_160000_1_1","364-160000.1.1"]