SUSE-SU-2026:1220-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20261220-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1220-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:1220-1
Upstream
Related
Withdrawn
2026-07-13T14:00:33Z
Published
2026-04-08T16:03:04Z
Modified
2026-07-13T14:00:33Z
Summary
Security update for python-poetry
Details

This update for python-poetry fixes the following issue:

  • CVE-2026-34591: From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary file write (bsc#1261383).
References

Affected packages