* Sat Aug 08 2026 mcepl@suse.com
- CVE-2026-6019 fix does not handle non-ascii chars correctly
(bsc#1263083) (internal SUSE bug so far, no CVE yet)
bsc1263083-http-cookies-atob-utf8.patch
* Thu Aug 06 2026 mcepl@suse.com
- Update bundled setuptools and pip wheels to
pip-22.3.1-py2.py3-none-any.whl and
setuptools-67.7.2-py2.py3-none-any.whl (bsc#1262467,
CVE-2026-3219, bsc#1263442, CVE-2026-6357, bsc#1263443,
CVE-2026-6357, bsc#1257599, CVE-2026-1703, bsc#1266669,
CVE-2026-8643)
* Fri Jul 31 2026 mcepl@cepl.eu
- CVE-2026-3276: Fix O(n^2) canonical ordering in
unicodedata.normalize() (bsc#1267581, gh#python/cpython#149079)
CVE-2026-3276-On2-unicodedata-normalize.patch
* Fri Jul 31 2026 mcepl@cepl.eu
- CVE-2026-0864: Normalize all line endings (CR, CRLF, and LF) in
configparser (bsc#1269066, gh#python/cpython#143927)
CVE-2026-0864-normalize-LFTAB-configparser.patch
* Fri Jul 31 2026 mcepl@cepl.eu
- CVE-2026-11972: Make tarfile._Stream.seek break at EOF
(bsc#1269788, gh#python/cpython#151981)
CVE-2026-11972-tarfile-Stream-seek-EOF.patch
* Fri Jul 31 2026 mcepl@cepl.eu
- CVE-2026-15308: Fix quadratic complexity in incremental parsing
in HTMLParser (bsc#1271192, gh#python/cpython#153030)
CVE-2026-15308-HTMLParser-CPU-exhaust.patch
* Sat Jul 04 2026 mcepl@cepl.eu
- CVE-2026-7210: Use XML_SetHashSalt16Bytes in
pyexpat/_elementtree when possible (bsc#1264962,
gh#python/cpython#149018).
CVE-2026-7210-pyexpat-entropy-hash-flooding.patch
* Thu Jul 02 2026 mcepl@cepl.eu
- CVE-2026-8328: Make ftplib not trust the PASV response
(bsc#1265268)
CVE-2026-8328-ftplib-no-trust-PASV-resp.patch
Version: 2.7.18-150000.120.1
* Wed May 13 2026 mcepl@suse.com
Add updated version of the pip wheel
pip-10.0.1-py2.py3-none-any.whl, which fixes:
- CVE-2026-6357: pip self-update functionality can import newly
installed modules after wheel installation (bsc#1263442)
- CVE-2026-3219: pip doesn't reject concatenated ZIP (bsc#1262429)
- CVE-2026-1703: (bsc#1257599, CVE-2026-1703, gh#pypa/pip#13777)
* Mon Apr 27 2026 mcepl@cepl.eu
- Add CVE-2026-6019-Morsel-js_output.patch protects against HTML
injection by Base64-encoding cookie values embedded in JS
(bsc#1262654, CVE-2026-6019, gh#python/cpython#90309).
* Sat Apr 25 2026 mcepl@cepl.eu
- Add CVE-2026-4786-webbrowser-open-action.patch, which fixes
webbrowser %action substitution bypass of dash-prefix check
(bsc#1262319, CVE-2026-4786, gh#python/cpython#148169).
* Fri Apr 24 2026 mcepl@cepl.eu
- Add CVE-2026-6100-use-after-free-decompression.patch preventing
dangling pointer which can end in the use-after-free error
(CVE-2026-6100, bsc#1262098, gh#python/cpython#148395).
* Thu Apr 09 2026 mcepl@suse.com
- Add skip-windows-test-aarch64.patch to skip obviously Windows
API test, which has no business to be tested on SLE-12/aarch64,
where it is failing.
- For SLE-12-SP1 use vendored libffi (bsc#1261652). We have
libffi4.so from SP3 only.
Version: 2.7.18-150000.111.1
* Fri Mar 27 2026 mcepl@cepl.eu
- Add CVE-2026-4519-webbrowser-open-dashes.patch to reject
leading dashes in webbrowser URLs (bsc#1260026, CVE-2026-4519,
gh#python/cpython#143930).
* Wed Mar 25 2026 mcepl@cepl.eu
- Add CVE-2025-13462-tarinfo-header-parse.patch which skips
TarInfo DIRTYPE normalization during GNU long name handling
(bsc#1259611, CVE-2025-13462).
* Mon Mar 23 2026 mcepl@cepl.eu
- Add CVE-2026-4224-expat-unbound-C-recursion.patch avoiding
unbound C recursion in conv_content_model in pyexpat.c
(bsc#1259735, CVE-2026-4224).
* Mon Mar 23 2026 mcepl@cepl.eu
- Add CVE-2026-3644-cookies-Morsel-update-II.patch to reject
control characters in http.cookies.Morsel.update() and
http.cookies.BaseCookie.js_output (bsc#1259734, CVE-2026-3644).
Version: 2.7.18-150000.105.1
* Wed Feb 25 2026 mcepl@suse.com
- Add CVE-2024-7592-quad-complex-cookies.patch (bsc#1229596,
CVE-2024-7592), which fixes quadratic complexity in parsing
"-quoted cookie values with backslashes by http.cookies.
* Sat Feb 14 2026 mcepl@suse.com
- CVE-2026-0672: rejects control characters in http cookies.
(bsc#1257031, gh#python/cpython#143919)
CVE-2026-0672-http-hdr-inject-cookie-Morsel.patch
- CVE-2026-0865: rejecting control characters in
wsgiref.headers.Headers, which could be abused for injecting
false HTTP headers. (bsc#1257042, gh#python/cpython#143916)
CVE-2026-0865-wsgiref-ctrl-chars.patch
- CVE-2025-15366: basically the same as the previous patch for
IMAP protocol. (bsc#1257044, gh#python/cpython#143921)
CVE-2025-15366-imap-ctrl-chars.patch
- CVE-2025-15367: basically the same as the previous patch for
poplib library. (bsc#1257041, gh#python/cpython#143923)
CVE-2025-15367-poplib-ctrl-chars.patch
* Fri Nov 14 2025 mcepl@suse.com
- Add CVE-2025-6075-expandvars-perf-degrad.patch avoid simple
quadratic complexity vulnerabilities of os.path.expandvars()
(CVE-2025-6075, bsc#1252974).
Version: 2.7.18-150000.102.1
* Fri Feb 13 2026 mcepl@suse.com
- CVE-2026-0672: rejects control characters in http cookies.
(bsc#1257031, gh#python/cpython#143919)
CVE-2026-0672-http-hdr-inject-cookie-Morsel.patch
- CVE-2026-0865: rejecting control characters in
wsgiref.headers.Headers, which could be abused for injecting
false HTTP headers. (bsc#1257042, gh#python/cpython#143916)
CVE-2026-0865-wsgiref-ctrl-chars.patch
- CVE-2025-15366: basically the same as the previous patch for
IMAP protocol. (bsc#1257044, gh#python/cpython#143921)
CVE-2025-15366-imap-ctrl-chars.patch
- CVE-2025-15367: basically the same as the previous patch for
poplib library. (bsc#1257041, gh#python/cpython#143923)
CVE-2025-15367-poplib-ctrl-chars.patch
* Fri Feb 13 2026 nico.krapp@suse.com
- Add add-zlib-eof-attribute.patch, needed for python-urllib3
CVE fix (bsc#1254867)