openSUSE Security Updates Address Remote Code Exec and CSS Injection Vulnerabilities

openSUSE Security Updates Address Remote Code Exec and CSS Injection Vulnerabilities

First seen 20 Jul 2026, 07:01 UTC Linuxsecurity 75% similarity 70.5

Article Content

Browse articles
ThreatCluster

openSUSE has released security updates for two vulnerabilities affecting its systems. The first, CVE-2026-0252, is a critical remote code execution vulnerability in the python-django-haystack package, which could allow attackers to execute arbitrary code. The second, CVE-2026-0251, is a moderate CSS injection vulnerability in the python-weasyprint package, potentially allowing for unauthorized content manipulation. Both vulnerabilities affect openSUSE Backports SLE-15-SP7. Users are advised to apply the patches using YaST online_update or zypper patch commands. The vulnerabilities were disclosed on July 19, 2026, and the updates are now available for installation. Immediate action is recommended to mitigate potential risks.

Key Points: • CVE-2026-0252 allows remote code execution in python-django-haystack. • CVE-2026-0251 presents a moderate CSS injection risk in python-weasyprint. • Users must apply patches immediately to secure affected openSUSE systems.

ThreatCluster AI

Timeline

2026-07-19
Security updates released for openSUSE vulnerabilities
openSUSE issued patches for CVE-2026-0252 and CVE-2026-0251, addressing critical and moderate vulnerabilities respectively.
Linuxsecurity
2026-07-19
CVE-2026-0252 disclosed
A critical remote code execution vulnerability in python-django-haystack was made public, affecting openSUSE Backports SLE-15-SP7.
Linuxsecurity
2026-07-19
CVE-2026-0251 disclosed
A moderate CSS injection vulnerability in python-weasyprint was disclosed, also impacting openSUSE Backports SLE-15-SP7.
Linuxsecurity

Community

Browse all →