This update for cockpit fixes the following issues
- CVE-2026-4802: remote command execution via unsanitized user-controlled parameters within crafted links in system logs
UI (bsc#1265040).
- CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive CPU and memory consumption and
may crash a Node.js process (bsc#1257836).