openSUSE Python Vulnerabilities: Arbitrary File Install and DoS Issues

openSUSE Python Vulnerabilities: Arbitrary File Install and DoS Issues

First seen 12 Aug 2026, 02:41 UTC Linuxsecurity 79% similarity 60.6

Article Content

Browse articles
ThreatCluster

Recent updates for openSUSE address two vulnerabilities in Python packages. CVE-2026-13346 in python-pip allows arbitrary file installations due to improper handling of doubly-encoded URLs from malicious indexes. This could lead to unauthorized file placements on affected systems. Additionally, a denial of service vulnerability in python3-sqlparse was fixed, which could disrupt services by improperly formatting lists of tuples. The updates were released on August 10 and 12, 2026, and users are advised to apply patches immediately to mitigate risks. Affected systems include various openSUSE and SUSE Linux Enterprise modules. The vulnerabilities highlight the importance of auditing Linux privileges to prevent escalation and damage.

Key Points: • CVE-2026-13346 allows arbitrary file installations via python-pip. • Denial of service vulnerability fixed in python3-sqlparse affects multiple products. • Immediate patching is recommended to mitigate risks from these vulnerabilities.

ThreatCluster AI How this analysis works

Timeline

2026-07-29
CVE-2026-13346 published
CVE-2026-13346 details improper URL handling in python-pip, enabling arbitrary file installations.
Linuxsecurity
2026-08-10
DoS vulnerability fixed in python3-sqlparse
SUSE released a patch for python3-sqlparse addressing a denial of service vulnerability affecting several products.
Linuxsecurity
2026-08-12
Patch released for python-pip vulnerability
openSUSE released an update for python-pip to fix CVE-2026-13346, addressing arbitrary file installation risks.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story